Skip to content
Call-on-Doc Data Breach Exposes Sensitive PHI and PII

Call-on-Doc Data Breach Exposes Sensitive PHI and PII

Claimdepot September 22, 2026

Call-on-Doc , a web-based telehealth platform based in Dallas, Texas, experienced a data breach between late December 2025 and early January 2026.

An unauthorized party gained access to Call-on-Doc's network between Dec. 22, 2025, and Jan. 3, 2026.

On Jan. 22, 2026, a threat actor using the name "iProfessor" posted on the open web claiming to be selling a database from Call-on-Doc. The threat actor alleged that the dataset contained 1,144,223 patient records tied to a breach dated December 2025. The data allegedly included patient names, details, addresses, medical categories and conditions, prescribed services, transaction numbers and payment amounts.

On Aug. 19, 2026, the company's investigation determined that protected health information had been potentially accessed or acquired by the unauthorized party during that window. These included patients' names, email addresses, physical addresses, phone numbers, medical diagnoses, medication information and visit types.

The incident has so far impacted 92,012 Texas residents .

The company disclosed the incident to the California Attorney General , as well as posted a notice on its website . The company began notifying affected consumers on Sept. 18, 2026, by U.S. Mail.

Call-on-Doc's response to the breach

Call-on-Doc's response to the breach

The company recommended that consumers take precautionary measures to protect their personal and medical information. These recommendations included monitoring credit files and reviewing medical-related documents for signs of potential misuse.

The notification letter to affected individuals provided information for the three major credit reporting agencies as well as information resources available through the Federal Trade Commission.

Call-on-Doc set up a dedicated call center for individuals with questions the incident. According to the notification letter, the response line is available for 90 days from the date of the letter, between 8 a.m. and 8 p.m. Eastern time, Monday through Friday, excluding holidays.

Social Security Numbers

Affected information types not yet disclosed

Extracted Entities

Attack Types (1)

Companies (1)