Were you recently affected by a data breach?

Vernon & Waldrep OB-Gyn Associates Data Breach

Vernon & Waldrep OB-Gyn Associates, a Dallas-area women’s healthcare provider, reported a data breach affecting more than 16,800 patients. Names, addresses, medical information, health insurance details, and dates of birth may have been exposed.

Vernon & Waldrep OB-Gyn Associates
Date of Breach: Reported to the Texas Attorney General on September 11, 2026
CAU logo

Who was affected:

Clients of Vernon & Waldrep OB-Gyn Associates

Impacted Data:

Names, addresses, dates of birth, medical information, health insurance information

Vernon & Waldrep OB-Gyn Associates, a women’s healthcare practice serving the greater Dallas, Texas area, has notified more than 16,800 patients that their personal and medical information may have been compromised in a data security incident. The practice reported the breach to the Texas Attorney General’s Office on September 11, 2026.

Healthcare providers are entrusted with some of the most sensitive information a person has, and when that information is exposed, patients can be left facing real consequences well beyond the initial notification letter.

Vernon & Waldrep OB-Gyn Associates’s Data Breach Investigation

According to the report filed with the Texas Attorney General, the breach affected names, addresses, medical information, health insurance information, and dates of birth belonging to more than 16,800 individuals. As of this writing, Vernon & Waldrep OB-Gyn Associates has not publicly disclosed the specific cause of the incident, how the affected systems were accessed, or the exact dates the breach occurred and was discovered.

Healthcare organizations, including smaller independent practices like OB-Gyn clinics, have become frequent targets for cyberattacks in recent years. Medical records and insurance information are especially valuable on the black market because, unlike a credit card number, they cannot simply be canceled and reissued after a breach. A stolen medical record can be used for years afterward to commit insurance fraud, obtain prescription drugs, or file fraudulent claims in a patient’s name.

The combination of data types reported in this incident is particularly concerning. Names paired with dates of birth and addresses give bad actors enough information to attempt identity theft, while medical and health insurance information can be used to file fraudulent medical claims or obtain treatment or medication under someone else’s identity. Victims of medical identity theft often don’t discover the problem until they receive a bill for services they never received, or until an insurance claim is denied because their benefits have already been exhausted by a fraudster.

State data breach notification laws generally require companies to notify affected individuals and regulators within a specific window after a breach is discovered, though the exact timeline requirements vary by state and by the number of residents affected. Filing a breach report with a state Attorney General’s office, as Vernon & Waldrep OB-Gyn Associates did with Texas, is a standard part of that regulatory process and does not by itself indicate the severity of the incident, only that state-mandated notification thresholds were met.

Patients affected by a healthcare data breach should also be alert to follow-up phishing attempts. It is common for scammers to use news of a real data breach to send fake notification emails or texts that appear to come from the breached company, attempting to trick victims into providing even more personal information or clicking on a malicious link. Any communication about this breach should be verified through Vernon & Waldrep OB-Gyn Associates’s official channels before responding or clicking any links.

When Did This Breach Occur?

Vernon & Waldrep OB-Gyn Associates’s report to the Texas Attorney General is dated September 11, 2026. The practice has not publicly released the specific dates the underlying incident began, was discovered, or was contained. Individuals with questions about the exact timeline should refer to any written notice sent directly by Vernon & Waldrep OB-Gyn Associates.

What Information Was Breached?

Based on the report filed with the Texas Attorney General, the following categories of information were involved in the breach:

Names, addresses, dates of birth, medical information, and health insurance information. Vernon & Waldrep OB-Gyn Associates has not disclosed whether additional data types, such as Social Security numbers or financial account information, were also affected.

What You Can Do

If you received a notification letter from Vernon & Waldrep OB-Gyn Associates, or believe you may have been affected by this breach, consider the following steps:

  • Carefully review any notification letter for specific instructions or offered protections, such as credit monitoring or identity theft protection services.
  • Monitor your health insurance Explanation of Benefits (EOB) statements for services you did not receive.
  • Watch financial accounts and credit reports for unfamiliar activity.
  • Be cautious of unsolicited calls, texts, or emails referencing this breach, and never click links or share information without independently verifying the sender.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus if you are concerned about identity theft.

File a Data Breach Lawsuit Against Vernon & Waldrep OB-Gyn Associates

If you were notified that your information was involved in the Vernon & Waldrep OB-Gyn Associates data breach, you may have legal options available to help recover losses related to the incident.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity detected December 30, 2025; notice filed with the New Hampshire Attorney General on September 1, 2026
Date of Breach: Reported to the Texas Attorney General on September 11, 2026
Date of Breach: Reported to be around May 25, 2026; formally reported to the Texas Attorney General on September 11, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.