Alexes Hazen, MD PLLC Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Alexes Hazen, MD PLLC notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 08, 2026, and the notice lists social security numbers, government ID numbers, financial account codes, credit and debit account info, health records among the information exposed.
Eight people received notice that their most sensitive personal records are now in unknown hands. The filing by Alexes Hazen, MD PLLC, submitted to the Vermont Attorney General on June 08, 2026, confirms that the exposed information includes Social Security numbers, government ID numbers, financial account codes, credit and debit account information, and health records.
Because these categories never expire, the consequences can last for decades. A stolen Social Security number combined with health records can be used to file fraudulent tax returns, open accounts in your name, or commit medical identity theft that contaminates your insurance history. Credit and debit account details add immediate fraud risk, while government ID numbers can help attackers build convincing synthetic identities.
Why These Eight Records Matter More Than the Small Number Suggests
The small headcount does not reduce the severity for those affected. When a medical practice holds both financial instruments and full health records alongside Social Security numbers, each person’s file becomes a complete package for long-term identity crimes. Unlike a lost credit card that can be canceled in minutes, a Social Security number cannot be replaced on demand. Health records cannot be changed at all.
The filing does not state when the incident occurred, so the only reliable way to determine whether you are one of the eight is to wait for direct notification from the practice. Letters are sent to the last known address. If you have moved since the incident, the letter may never reach you. In that case, contact Alexes Hazen, MD PLLC directly to confirm whether your records were included.
What a Social Security Number and Health Records Enable Together
Attackers who obtain both pieces can impersonate you at hospitals or clinics to receive treatment charged to your insurance. They can file false tax returns before you do, locking you out of refunds. They can apply for government benefits or new credit lines using your government ID numbers as supporting documentation.
Credit and debit account information listed in the filing increases the chance of immediate unauthorized charges. Financial account codes can be used to access existing accounts or set up new ones. None of these identifiers can simply be rotated like a password. Once they are out, they remain usable indefinitely.
No Passwords Were Exposed
The record contains no indication that login credentials were compromised. This is genuinely good news. You do not need to change any password connected to this practice because of this incident. The risk lies entirely in the non-resettable identifiers and the sensitive medical and financial details themselves.
The Permanent Nature of What Was Lost
Health records and Social Security numbers create lifelong exposure. Medical identity theft can lead to incorrect information being added to your permanent health file, potentially affecting future treatment decisions. Government ID numbers and financial account codes can be reused in schemes that surface years later.
Because the filing lists these categories without assigning them to specific individuals, your own notification letter is the only document that will tell you exactly which pieces of information were involved in your case. Do not assume every category applies to you, but treat the worst-case combination as possible until you know otherwise.
How to Check Whether This Affects You
The organization is required to notify affected individuals directly, usually by mail. Absence of a letter is usually a strong sign that your records were not part of the eight affected. However, anyone who has changed address since the incident should reach out to Alexes Hazen, MD PLLC to verify their status. Do not rely on the passage of time or lack of immediate fraud as proof of safety.
Protecting Yourself When Identifiers Cannot Be Changed
Place a fraud alert with the three major credit bureaus so lenders must verify your identity before opening new accounts. Monitor your Explanation of Benefits statements from every health insurer you use; unauthorized claims often appear there first. Review tax transcripts from the IRS each year to catch fraudulent filings early.
Consider freezing your credit reports. This stops most new credit applications in their tracks and is the strongest control available when a Social Security number is no longer private. Continue monitoring bank and credit card statements for unusual activity even after any immediate cards are replaced.
These steps cannot undo the exposure, but they limit what attackers can do with the information. The filing establishes that eight people’s sensitive records left the practice’s control. For those eight, the exposure is permanent. The only remaining variable is how quickly and effectively they respond.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Alexes Hazen, MD PLLC.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…