Utopia Tech
Healthcare3 min read

Call-on-Doc Notifies Patients About December 2025 Hacking Incident

The telemedicine platform operator Call-on-Doc has notified patients about a December 2025 cyberattack and data breach. Data breaches have also been announced by Provident Behavioral Health, Vernon & Waldrep OB-Gyn Associates, and Partnership HealthPlan of California. Call-on-Doc Call-on-Doc, Inc., a Dallas, Texas-based online telemedicine platform provider, started issuing not

UT

Utopia Tech

September 22, 2026 · 3 min read

Share

The telemedicine platform operator Call-on-Doc has notified patients about a December 2025 cyberattack and data breach. Data breaches have also been announced by Provident Behavioral Health, Vernon & Waldrep OB-Gyn Associates, and Partnership HealthPlan of California. Call-on-Doc Call-on-Doc, Inc.

, a Dallas, Texas-based online telemedicine platform provider, started issuing notification letters on September 18, 2026, about a cybersecurity incident that occurred in December 2025. Suspicious activity was identified within its computer systems on December 28, 2025. The forensic investigation determined that an unauthorized third party had access to its network from December 22, 2025, to January 3, 2026.

The affected parts of its network were reviewed, and on August 19, 2026, it was confirmed that protected health information was compromised in the incident. The types of data involved vary from individual to individual and may include names, email addresses, physical addresses, phone numbers, diagnoses, medical information, and visit types. Call-on-Doc said it has not detected any instances of fraud related to the incident.

The notifications do not provide any further information on the nature of the attack; however, a threat actor claimed responsibility for the attack and attempted to sell the stolen data in January 2026. The threat actor claimed to have stolen personal and medical information of more than 1. 1 million individuals, although that claim has not been verified.

Call-on-Doc has not yet publicly disclosed how many individuals were affected by the incident, and the incident is not currently shown on the HHS’ Office for Civil Rights website. Provident Behavioral Health Provident Behavioral Health, a St. Louis, Missouri-based provider of counselling and psychiatric services, has disclosed a data breach involving the protected health information of 25,086 individuals.

Unusual activity was identified within its computer systems on April 3, 2026. The impacted systems were isolated, and a third-party cybersecurity firm was engaged to conduct a forensic investigation and remediate the issue. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.

Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The forensic investigation found evidence that files stored on the impacted systems were acquired by an unauthorized third party. The data review has recently been completed and confirmed that data compromised in the incident included names, contact information, demographic information, birth dates, Social Security numbers, driver’s license numbers, medical information, and health insurance information.

All administrative credentials have been changed, and security measures have been enhanced to reduce the risk of similar incidents in the future. The affected individuals were notified on September 4, 2026. Vernon & Waldrep OB-Gyn Associates Vernon & Waldrep OB-Gyn Associates, a Dallas, Texas-based women’s healthcare practice, has notified 16,876 patients about a network intrusion that exposed patients’ personal and protected health information.

The intrusion was identified on July 28, 2026, and immediate action was taken to secure its network and prevent further unauthorized access. The forensic investigation determined that a threat actor accessed systems containing patient data such as names, addresses, phone numbers, dates of birth, treatment and diagnosis information, claims information, medical provider names, lab test results, and health insurance information.

Vernon & Waldrep said it has not identified any misuse of the affected data. While not mentioned in the notification letters, a ransomware group called Global Secret Group claimed responsibility for the attack on August 1, 2026, alleging that 274 GB of data was stolen, including patient records. Partnership HealthPlan of California Partnership HealthPlan of California, a Fairfield, California-based managed care provider, has notified 1,526 individuals about a breach of their protected health information.

According to the notification letters, a privacy incident was identified on July 7, 2026, involving Primary Care Physician (PCP) Selection Forms and Welcome Packets. The investigation determined that certain mailings were sent between May 13, 2026, and July 8, 2026, that contained information of unrelated members. Mailings included another individual’s name, date of birth, and membership identification number.

Partnership HealthPlan of California said it has reviewed and strengthened its privacy and security safeguards, provided additional workforce training, and taken other steps to prevent similar incidents in the future. The post Call-on-Doc Notifies Patients About December 2025 Hacking Incident appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content