University Surgical Associates, PLLC, a healthcare provider, has notified state regulators of a data security incident affecting patients. The company reported to the Vermont Attorney General’s office that patients’ Social Security numbers and health records were compromised. Healthcare providers maintain some of the most sensitive personal information that exists, and when that information is exposed, patients can be left vulnerable to identity theft and medical fraud for years afterward.
University Surgical Associates, PLLC’s Data Breach Investigation
University Surgical Associates, PLLC submitted a formal notice to the Vermont Attorney General’s Consumer Assistance Program confirming that at least five Vermont residents were affected by a breach involving Social Security numbers and health records. As of this writing, the company has not issued a detailed public statement describing the nature of the incident, how the unauthorized access or disclosure occurred, or whether the exposure resulted from a cyberattack, an internal error, or another cause. State data breach notification laws generally require companies to notify affected residents and the relevant state attorney general’s office once a determination is made that personal information was compromised, and many states require this notification even when the number of that state’s affected residents is small. A filing covering only a handful of Vermont residents can therefore still be part of a larger breach affecting patients or clients in other states as well, since companies are typically required to file separate notices in each state where affected individuals reside.
Healthcare providers have become one of the most frequently targeted categories of organization for data breaches and cyberattacks, in large part because medical practices store a dense combination of Social Security numbers, insurance information, and detailed health records, all of which carry significant value on illicit markets. Health records in particular can be used to commit medical identity theft, including fraudulently obtaining prescription medications, submitting false insurance claims, or receiving medical treatment under another person’s identity, which can create billing and treatment-history complications that are often difficult and time-consuming for victims to untangle. The combination of a Social Security number with health records, as reported in this incident, is considered a high-value pairing for that reason.
Because University Surgical Associates has not publicly detailed the cause of the incident, it is not yet known whether the exposure stemmed from a targeted cyberattack, a third-party vendor incident, or another type of security failure. Companies that experience a data security incident are generally expected to conduct a forensic investigation, determine the scope of what was accessed, and notify affected individuals directly with instructions on any protective steps being offered, such as credit monitoring or identity theft protection services. Individuals who receive a direct notification letter from the practice should review it carefully, as it may contain information specific to their own exposure that is not part of the public regulatory filing.
When Did This Breach Occur?
University Surgical Associates, PLLC’s notice to the Vermont Attorney General was filed on August 24, 2026. The company has not publicly disclosed the date on which the underlying incident occurred or when it was first discovered internally.
What Information Was Breached?
According to the notice filed with the Vermont Attorney General, the compromised information included patients’ Social Security numbers and health records. University Surgical Associates has not published a more detailed breakdown of the specific data elements involved for each affected individual. Anyone who receives a direct notification letter should treat it as the most reliable source of information about what data specific to them may have been exposed.
What You Can Do
If you are a current or former patient of University Surgical Associates, PLLC, consider taking the following steps to protect yourself:
- Review any notification letter you receive from the practice carefully and follow its specific instructions.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Request and review your medical records and insurance claim history for entries you don’t recognize.
- Monitor your Explanation of Benefits statements from your health insurer for unfamiliar charges.
- Be cautious of unsolicited calls, emails, or texts referencing this breach, which could be phishing attempts.
- Consider enrolling in any credit monitoring or identity protection service the practice offers.
File a Data Breach Lawsuit Against University Surgical Associates, PLLC
If your personal or health information was exposed as a result of this incident, you may be entitled to compensation. Healthcare providers have a legal responsibility to protect the sensitive patient data they collect and store, and when that data is compromised, affected patients may have grounds to pursue legal action.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.