The trail at Doctor’s Choice Home Care leads outward, not inward: patient records at the Houston home health and hospice provider were reached through its electronic medical record vendor’s platform rather than its own network.
The provider’s own account of the incident, published as a website notice, puts the activity inside the records platform. One clinical user account in the WellSky electronic medical record system was used by an unauthorized party across a seven-week span, from early June to late July 2026, with discovery landing on July 21. Texas regulators were told 14,333 residents were caught up.
The notification lists a clinical and financial mix of exposed fields, including treatment information and insurance data, appointment scheduling, Social Security numbers, dates of birth and identifying details.
Nothing in the provider’s own environment pointed to a wider compromise; the unauthorized activity the review surfaced sat entirely within the vendor’s platform. That conclusion shapes how the case is handled, because it shifts much of the forensic work and the notification duty onto a third party most patients never chose directly.
Vendor concentration is a recurring theme in healthcare breaches. A shared platform used by many providers can turn one compromised account into an event that surfaces across several organizations at once, and the patients in the middle often learn about it from a company name they do not recognize.
For provider security teams, the case raises a basic question: how quickly would you know if an account you do not manage was being used against your patients’ records?