American Association of Colleges of Osteopathic Medicine Data Breach Notice (Oregon Attorney General)
If you received a notice from American Association of Colleges of Osteopathic, here’s what the filing says was exposed, and what to do about it.
American Association of Colleges of Osteopathic Medicine notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 08, 2025. The filing puts the incident itself on September 26, 2024.
The American Association of Colleges of Osteopathic Medicine notified Oregon residents that personal information belonging to 67,804 people was exposed in an incident that occurred on September 26, 2024. The organization filed the notice with the Oregon Department of Justice on April 08, 2025 — 194 days later.
If you received a letter from the organization, your records were among those affected. The filing does not state exactly which specific pieces of personal information applied to each individual, only that personal information was exposed in the incident. Anyone who has moved since September 2024 should contact the association directly to confirm whether their information was included, as notification letters are sent to the last known address.
Personal Information That Cannot Be Replaced
Once personal information such as your name combined with a Social Security number or date of birth leaves an organization’s systems, it remains valuable to identity thieves for years. Unlike a credit card or password, these details cannot be cancelled or reissued. The 194-day gap between the incident and the filing means that information has had a long window to circulate before anyone outside the organization was told.
This exposure creates a permanent risk of identity theft and tax fraud. Thieves can use the combination of your name and Social Security number to open accounts, file fraudulent tax returns, or apply for government benefits in your name. The longer the information is out there, the higher the chance it has reached criminals who specialize in long-term identity abuse.
What the Filing Does Not Tell You
The record lists only “personal information” and does not disclose whether passwords, financial account numbers, medical details, or any other specific categories were involved. No passwords were exposed. This means you do not need to change any password connected to the American Association of Colleges of Osteopathic Medicine because none was compromised in this incident.
The filing also provides no information about how the breach occurred, whether data was stolen or simply accessed, or how long any unauthorized access lasted. Those details remain unknown to the public. What matters most is the outcome: personal information belonging to 67,804 individuals is now outside the organization’s control.
How This Exposure Usually Plays Out
Criminals who obtain names and Social Security numbers rarely use them immediately. They often hold the data for months or years, waiting for the right opportunity. This delay is why many people first learn of a breach like this when they are rejected for a loan, receive an unexpected tax notice, or see unfamiliar accounts appear on their credit report long after the original incident.
The scale — more than 67,000 people — makes the data set attractive to professional fraud rings. Larger batches allow them to spread attempts across many victims, reducing the chance that any single suspicious activity triggers immediate alerts.
Practical Steps That Address This Specific Exposure
- Place a fraud alert or credit freeze with the three major credit bureaus immediately. This is the single most effective action you can take. A freeze stops new accounts from being opened in your name without your direct permission.
- Monitor your credit reports weekly for the next year. You are entitled to free weekly reports from AnnualCreditReport.com. Look for accounts or inquiries you do not recognize.
- File your taxes early and respond quickly to any IRS notices. Tax refund fraud is one of the most common consequences of Social Security number exposure. Submitting your return before thieves can file a fraudulent one reduces that risk.
- Review Explanation of Benefits statements from any health plans. Even though medical information is not explicitly listed, watch for claims filed in your name that you did not receive care for.
- Contact the American Association of Colleges of Osteopathic Medicine directly if you have not received a letter but believe you may have been a student, applicant, or employee during the relevant period. Only they can confirm whether your specific records were in the affected group.
The most important reality is that this exposure is now permanent. You cannot make the information disappear, but you can make it far harder for criminals to use it against you. Acting quickly on credit monitoring and tax vigilance gives you the greatest control over what happens next.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…