Call-on-Doc, a Dallas telemedicine operator, started sending breach notices on September 18 to patients whose health records an intruder could open for roughly two weeks last winter.
The company spotted something wrong on December 28, 2025. A forensic review later traced the intruder’s network access to a stretch of about two weeks, from December 22, 2025 to January 3, 2026. Only on August 19, 2026 – nearly eight months after that access ended – did Call-on-Doc confirm that protected health information had been caught up in the incident.
The categories exposed are not identical for every patient. Depending on the individual, the records could hold diagnoses and visit types, medical information, phone numbers, physical or email addresses, and names. Call-on-Doc says it has found no fraud tied to the event, and the notices leave out any detail on the method used.
A threat actor took credit for the intrusion in January 2026 and tried to sell the records, claiming more than 1.1 million people were affected. Call-on-Doc has neither verified that figure nor published a count of its own. The incident does not appear on the HHS Office for Civil Rights breach portal, so no official total exists.
Telemedicine concentrates clinical detail behind one login, and that is what draws crews who trade in medical data instead of encrypting it. The compliance lesson here is about timing: when a forensic review drags, the distance between containment and patient notification can run well beyond the 60-day window regulators expect.