DataBreachLegalCenter.com
MonitoringTexas AG filing · September 15, 2026

Catalyst Physician Group Notifies Patients of 2025 Data Exposure

Catalyst Physician Group reported an unspecified data breach in 2026, impacting patient information from late 2025. Individuals who received a notification letter should review its details to understand the specific risks to their personal and medical data.

State
Texas
Breach date
December 2, 2025
Reported
September 15, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

Catalyst Physician Group, a prominent healthcare provider in Texas, announced a data security incident that occurred on December 2, 2025. The breach was reported to authorities on September 15, 2026, though the specific nature of how the intrusion occurred remains undisclosed. While the investigation is ongoing, patients who received a data breach notification letter should understand what this means for their personal information.

The reported exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The combination of these sensitive details could lead to various forms of identity theft and fraud.

As a healthcare entity, Catalyst Physician Group is responsible for protecting patient data under laws like the Health Insurance Portability and Accountability Act (HIPAA) and the Texas Medical Records Privacy Act. These regulations require robust security measures to prevent unauthorized access to sensitive personal and medical records.

Receiving an official data breach notification letter from Catalyst Physician Group confirms that your confidential information was exposed. This letter serves as a crucial document in understanding the extent of the exposure and your legal standing.

It is important for affected individuals to recognize the long-term risks associated with exposed medical and personal data. Unlike a credit card, this information cannot simply be cancelled or replaced. Understanding the details in your notification letter is the first step toward safeguarding your identity and rights.

If you have received a data breach notification letter from Catalyst Physician Group, you may be entitled to legal recourse. We offer a free, no-obligation case review to help you understand your options and discuss whether you may be eligible to pursue a claim. There is no cost to you unless we successfully recover compensation.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Texas Attorney General filing

Related data breach cases