DataBreachLegalCenter.com
MonitoringTexas AG filing · September 17, 2026

Three Oaks Hospice of Austin Data Breach Exposes Patient Records

Three Oaks Hospice of Austin reported a data breach affecting patient information, with the incident occurring in July 2025 and reported in September 2026. This exposure highlights the ongoing risks to sensitive medical and personal data entrusted to healthcare providers.

State
Texas
Breach date
July 16, 2025
Reported
September 17, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Home Address and Contact Details

Three Oaks Hospice of Austin, a provider of palliative and end-of-life care in Texas, has reported a data breach that began on July 16, 2025. The organization filed notice of the incident on September 17, 2026, indicating unauthorized access to its digital systems.

While the specific technical details of how the breach occurred are still under investigation, incidents like this often involve third-party access to network environments, potentially leading to the exfiltration of confidential patient records. Healthcare entities manage a vast amount of sensitive personal and health information, making them frequent targets for cyberattacks.

According to the disclosure, the exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Home Address and Contact Details. This combination of identifying and health-related information can pose significant risks to affected individuals.

The exposure of such deeply personal information can lead to various forms of identity theft and fraud, including medical identity theft where criminals might use your information to obtain medical services or file fraudulent claims. Unlike credit card numbers, which can be easily changed, compromised medical records and Social Security Numbers are permanent and can have long-lasting consequences.

If you received a data breach notification letter from Three Oaks Hospice of Austin, it confirms that your personal and health information was involved in this security incident. Understanding the contents of this letter is an important step in knowing how to protect yourself.

Organizations like Three Oaks Hospice of Austin are legally obligated to safeguard the data they collect. When a breach occurs, it often points to potential failures in security protocols. Affected individuals may have legal standing to seek recourse, even if they have not yet experienced direct financial harm, due to the increased risk posed by such an exposure.

We are currently investigating the Three Oaks Hospice of Austin data breach and are available to discuss the specifics of your situation. A free case review can help you understand what this incident means for you and explore any potential next steps you might consider.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Texas Attorney General filing

Related data breach cases