Were you recently affected by a data breach?

University Surgical Associates, PLLC Data Breach

University Surgical Associates, PLLC notified Vermont regulators that patients’ Social Security numbers and health records were exposed in a data security incident. Affected patients may have legal options.

University Surgical Associates, PLLC
Date of Breach: not publicly disclosed
CAU logo

Who was affected:

Clients of University Surgical Associates, PLLC

Impacted Data:

Social Security numbers and health records, according to University Surgical Associates, PLLC’s notice to the Vermont Attorney General. The company has not publicly disclosed the specific cause of the incident or additional details about how the data was compromised.

University Surgical Associates, PLLC, a healthcare provider, has notified state regulators of a data security incident affecting patients. The company reported to the Vermont Attorney General’s office that patients’ Social Security numbers and health records were compromised. Healthcare providers maintain some of the most sensitive personal information that exists, and when that information is exposed, patients can be left vulnerable to identity theft and medical fraud for years afterward.

University Surgical Associates, PLLC’s Data Breach Investigation

University Surgical Associates, PLLC submitted a formal notice to the Vermont Attorney General’s Consumer Assistance Program confirming that at least five Vermont residents were affected by a breach involving Social Security numbers and health records. As of this writing, the company has not issued a detailed public statement describing the nature of the incident, how the unauthorized access or disclosure occurred, or whether the exposure resulted from a cyberattack, an internal error, or another cause. State data breach notification laws generally require companies to notify affected residents and the relevant state attorney general’s office once a determination is made that personal information was compromised, and many states require this notification even when the number of that state’s affected residents is small. A filing covering only a handful of Vermont residents can therefore still be part of a larger breach affecting patients or clients in other states as well, since companies are typically required to file separate notices in each state where affected individuals reside.

Healthcare providers have become one of the most frequently targeted categories of organization for data breaches and cyberattacks, in large part because medical practices store a dense combination of Social Security numbers, insurance information, and detailed health records, all of which carry significant value on illicit markets. Health records in particular can be used to commit medical identity theft, including fraudulently obtaining prescription medications, submitting false insurance claims, or receiving medical treatment under another person’s identity, which can create billing and treatment-history complications that are often difficult and time-consuming for victims to untangle. The combination of a Social Security number with health records, as reported in this incident, is considered a high-value pairing for that reason.

Because University Surgical Associates has not publicly detailed the cause of the incident, it is not yet known whether the exposure stemmed from a targeted cyberattack, a third-party vendor incident, or another type of security failure. Companies that experience a data security incident are generally expected to conduct a forensic investigation, determine the scope of what was accessed, and notify affected individuals directly with instructions on any protective steps being offered, such as credit monitoring or identity theft protection services. Individuals who receive a direct notification letter from the practice should review it carefully, as it may contain information specific to their own exposure that is not part of the public regulatory filing.

When Did This Breach Occur?

University Surgical Associates, PLLC’s notice to the Vermont Attorney General was filed on August 24, 2026. The company has not publicly disclosed the date on which the underlying incident occurred or when it was first discovered internally.

What Information Was Breached?

According to the notice filed with the Vermont Attorney General, the compromised information included patients’ Social Security numbers and health records. University Surgical Associates has not published a more detailed breakdown of the specific data elements involved for each affected individual. Anyone who receives a direct notification letter should treat it as the most reliable source of information about what data specific to them may have been exposed.

What You Can Do

If you are a current or former patient of University Surgical Associates, PLLC, consider taking the following steps to protect yourself:

  • Review any notification letter you receive from the practice carefully and follow its specific instructions.
  • Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
  • Request and review your medical records and insurance claim history for entries you don’t recognize.
  • Monitor your Explanation of Benefits statements from your health insurer for unfamiliar charges.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, which could be phishing attempts.
  • Consider enrolling in any credit monitoring or identity protection service the practice offers.

File a Data Breach Lawsuit Against University Surgical Associates, PLLC

If your personal or health information was exposed as a result of this incident, you may be entitled to compensation. Healthcare providers have a legal responsibility to protect the sensitive patient data they collect and store, and when that data is compromised, affected patients may have grounds to pursue legal action.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: not publicly disclosed
Date of Breach: Reported August 2026 (unconfirmed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.