Vernon & Waldrep OB-Gyn Associates, a women’s healthcare practice serving the greater Dallas, Texas area, has notified more than 16,800 patients that their personal and medical information may have been compromised in a data security incident. The practice reported the breach to the Texas Attorney General’s Office on September 11, 2026.
Healthcare providers are entrusted with some of the most sensitive information a person has, and when that information is exposed, patients can be left facing real consequences well beyond the initial notification letter.
Vernon & Waldrep OB-Gyn Associates’s Data Breach Investigation
According to the report filed with the Texas Attorney General, the breach affected names, addresses, medical information, health insurance information, and dates of birth belonging to more than 16,800 individuals. As of this writing, Vernon & Waldrep OB-Gyn Associates has not publicly disclosed the specific cause of the incident, how the affected systems were accessed, or the exact dates the breach occurred and was discovered.
Healthcare organizations, including smaller independent practices like OB-Gyn clinics, have become frequent targets for cyberattacks in recent years. Medical records and insurance information are especially valuable on the black market because, unlike a credit card number, they cannot simply be canceled and reissued after a breach. A stolen medical record can be used for years afterward to commit insurance fraud, obtain prescription drugs, or file fraudulent claims in a patient’s name.
The combination of data types reported in this incident is particularly concerning. Names paired with dates of birth and addresses give bad actors enough information to attempt identity theft, while medical and health insurance information can be used to file fraudulent medical claims or obtain treatment or medication under someone else’s identity. Victims of medical identity theft often don’t discover the problem until they receive a bill for services they never received, or until an insurance claim is denied because their benefits have already been exhausted by a fraudster.
State data breach notification laws generally require companies to notify affected individuals and regulators within a specific window after a breach is discovered, though the exact timeline requirements vary by state and by the number of residents affected. Filing a breach report with a state Attorney General’s office, as Vernon & Waldrep OB-Gyn Associates did with Texas, is a standard part of that regulatory process and does not by itself indicate the severity of the incident, only that state-mandated notification thresholds were met.
Patients affected by a healthcare data breach should also be alert to follow-up phishing attempts. It is common for scammers to use news of a real data breach to send fake notification emails or texts that appear to come from the breached company, attempting to trick victims into providing even more personal information or clicking on a malicious link. Any communication about this breach should be verified through Vernon & Waldrep OB-Gyn Associates’s official channels before responding or clicking any links.
When Did This Breach Occur?
Vernon & Waldrep OB-Gyn Associates’s report to the Texas Attorney General is dated September 11, 2026. The practice has not publicly released the specific dates the underlying incident began, was discovered, or was contained. Individuals with questions about the exact timeline should refer to any written notice sent directly by Vernon & Waldrep OB-Gyn Associates.
What Information Was Breached?
Based on the report filed with the Texas Attorney General, the following categories of information were involved in the breach:
Names, addresses, dates of birth, medical information, and health insurance information. Vernon & Waldrep OB-Gyn Associates has not disclosed whether additional data types, such as Social Security numbers or financial account information, were also affected.
What You Can Do
If you received a notification letter from Vernon & Waldrep OB-Gyn Associates, or believe you may have been affected by this breach, consider the following steps:
- Carefully review any notification letter for specific instructions or offered protections, such as credit monitoring or identity theft protection services.
- Monitor your health insurance Explanation of Benefits (EOB) statements for services you did not receive.
- Watch financial accounts and credit reports for unfamiliar activity.
- Be cautious of unsolicited calls, texts, or emails referencing this breach, and never click links or share information without independently verifying the sender.
- Consider placing a fraud alert or credit freeze with the major credit bureaus if you are concerned about identity theft.
File a Data Breach Lawsuit Against Vernon & Waldrep OB-Gyn Associates
If you were notified that your information was involved in the Vernon & Waldrep OB-Gyn Associates data breach, you may have legal options available to help recover losses related to the incident.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.