Farrell Fritz, P.C. Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Farrell Fritz, P.C. notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on April 29, 2026, and the notice lists social security numbers, financial account codes, credit or debit account info, health records among the information exposed.
The April 29, 2026 filing from Farrell Fritz, P.C. states that information belonging to 12 Vermont residents was exposed. The categories listed are Social Security Numbers, financial account codes, credit or debit account information, and health records.
A Social Security Number cannot be replaced
If your SSN was among the records included, it remains permanently tied to your identity. Unlike a credit card or password, it cannot be reissued on request. This single number, paired with your name, allows someone to open accounts, file fraudulent tax returns, or apply for government benefits in your name. The risk does not expire when the news cycle moves on.
Health records carry similar lifelong weight. They can be used to commit medical identity theft, such as obtaining care under your insurance or filing false claims that later appear on your Explanation of Benefits. Financial account codes and credit or debit card details add immediate fraud potential, though those can usually be replaced once discovered.
What this exposure actually enables
With a Social Security Number and health records, a criminal can build a convincing synthetic identity or impersonate you in situations that require both government ID and medical history. Credit or debit account information accelerates direct theft before the accounts can be frozen. The filing does not state that every one of the 12 individuals had all four categories exposed; each person’s letter will list what applied to them.
No passwords were exposed. That is genuine good news. You do not need to change any password for Farrell Fritz, P.C. because none was included in this incident.
The letter is the only reliable check
The organisation is required to notify affected individuals directly, usually by post. If you have not received a letter from Farrell Fritz, P.C., it is likely your information was not part of the 12 records included. However, if you have moved since the incident occurred, the letter may have gone to an old address. In that case, contact the firm directly to confirm whether your records were involved.
Why these 12 records matter more than the small headcount suggests
Twelve people is a small number, yet the categories chosen are among the most damaging possible. A single accurate SSN combined with health records creates identity theft material that retains value for years. Financial account codes lower the bar for immediate fraud. The combination turns a modest breach into a high-impact event for anyone whose data was taken.
What remains under your control
You cannot change your SSN or erase health records already released. You can, however, limit what criminals can do with them. Monitoring and rapid response are now the primary defenses. The filing does not disclose the root cause, whether encryption was used, or how the data was accessed. Those details remain unknown to the public.
Placing the incident in context
This is not a mass breach affecting thousands. The precise number of 12 affected Vermont residents appears in the official filing. The small scale does not reduce the seriousness for those twelve people; it simply means the majority of clients and patients of Farrell Fritz, P.C. were not included.
Because the record lists both government identifiers and sensitive health data, the consequences are permanent for the individuals affected. Credit and debit account information can be canceled and reissued, but the SSN and health records cannot. That distinction shapes every protective step that follows.
Concrete steps that address this exact exposure
- Place a fraud alert or credit freeze with the three major bureaus immediately. A freeze stops new accounts from being opened in your name using the exposed SSN. It is free and reversible.
- Review every Explanation of Benefits statement from your health insurer. Look for services you did not receive. Medical identity theft often surfaces here first.
- Monitor all financial accounts listed in your notification letter for unfamiliar charges. Replace any compromised cards and request new account numbers.
- File your taxes early and respond quickly to any IRS notices. Fraudulent returns filed with a stolen SSN are a common next step.
- Request your free annual credit reports and check them for accounts you did not open. Continue checking every four months by rotating between Equifax, Experian, and TransUnion.
The filing from Farrell Fritz, P.C. contains only the facts required by Vermont law: who filed, when, which categories were involved, and how many people. It does not reveal the method of access or the organisation’s internal security posture. Those questions remain unanswered in the public record.
For the 12 individuals named, the exposure of Social Security Numbers and health records creates a permanent risk that must be managed for years. The letter you may or may not have received is still the clearest signal of whether you are one of them. If uncertainty remains, contacting Farrell Fritz, P.C. directly is the only way to settle it.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Farrell Fritz, P.C..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…