Jeffrey David Reuben, M.D. Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Jeffrey David Reuben, M.D. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on July 28, 2026, and the notice lists social security numbers, medical records and driver's license numbers among the information exposed.
The filing from Jeffrey David Reuben, M.D. means that three Massachusetts residents now face lifelong identity risks that cannot be undone. Social Security numbers and medical records do not expire. Once they are exposed, the potential for fraud, tax fraud, and medical identity theft remains for decades.
Three people. Three permanent records.
This is an unusually small breach, yet its impact on those affected is outsized precisely because the categories listed cannot be replaced. The notice lists Social Security numbers, medical records, and driver’s license numbers. No passwords were exposed. That single fact removes one major category of immediate worry: no one needs to rush to change credentials for this provider.
What a Social Security number combined with a driver’s license actually enables
A Social Security number paired with a driver’s license number is enough to open new financial accounts, file fraudulent tax returns, or apply for government benefits in someone else’s name. These two pieces of information together are frequently used to build synthetic identities. The addition of medical records increases the danger further. Someone with access to both your SSN and your treatment history can impersonate you at hospitals or clinics, potentially altering records, filing false claims, or obtaining prescriptions.
Medical identity theft is often discovered years later when a patient sees unfamiliar charges on an Explanation of Benefits statement or is denied coverage because their lifetime limits appear exhausted. Unlike credit card fraud, these consequences do not resolve in thirty days. They can follow a person for the rest of their life.
The letter is the only reliable way to know if this concerns you
Jeffrey David Reuben, M.D. is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely that your records were not among the three affected. However, if you have moved since the incident, the letter may have gone to an old address. In that case you should contact the practice directly to confirm whether you were included. The filing does not state when the incident occurred, only that the notification was filed on July 28, 2026. The letter therefore remains the single practical test available.
Why medical records retain their value long after the breach
Health information tied to a name and SSN creates a complete profile that identity thieves prize. It can be used to request additional medical services, order expensive equipment billed to your insurance, or even support fraudulent disability claims. Once stolen, this data circulates on dark-web markets for years because it cannot be reissued like a credit card or driver’s license. The three people named in this filing will need to monitor their medical and financial lives indefinitely.
The practical difference between what you can fix and what you cannot
A driver’s license number can be replaced by your state motor vehicle department. A Social Security number cannot. You will carry the same nine digits for the rest of your life. That permanence changes how you must defend yourself. Credit monitoring and fraud alerts become ongoing necessities rather than temporary precautions. Medical records require their own separate vigilance because the harm may surface through insurance statements rather than credit reports.
Placing the risk in context
With only three people affected, this incident is limited in scale. The small number does not reduce the severity for those three individuals. Each of them now holds a permanent, unchangeable identifier that has left their control. The exposure of medical records alongside government identifiers creates overlapping risks that touch both financial identity and personal health privacy.
What you should watch for in the coming years
Expect to see attempts to open accounts you did not request. Watch for tax transcripts you never asked for. Review every Explanation of Benefits statement from your health insurers even if you have not visited a doctor. Question any unexpected medical bills or collection notices. These are the practical signs that someone is using the exposed information.
Because the Social Security number cannot be changed, the burden of defense falls on detection and rapid response. Early discovery remains the most effective tool available once prevention is no longer possible.
Actions worth taking now
- Place a fraud alert or credit freeze with the three major credit bureaus. This is the single most effective step to stop new accounts from being opened in your name using the exposed Social Security number.
- Review every Explanation of Benefits statement from your health insurance carriers. Look for services you did not receive. Medical identity theft is frequently spotted first through insurance paperwork.
- File your taxes as early as possible each year. This reduces the window during which someone could file a fraudulent return using your SSN.
- Request your Social Security earnings statement annually. Check for earnings reported by employers you never worked for.
- Contact Jeffrey David Reuben, M.D. directly if you have moved recently or never received a letter. Confirm whether your records were part of the three affected so you know exactly which categories apply to you.
The exposure of these three records does not require panic, but it does require sustained attention. Social Security numbers and medical histories do not age out of usefulness to criminals. The steps above cannot undo what has already happened, yet they remain the most reliable ways to limit further damage over the long term.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Jeffrey David Reuben, M.D..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…