Minnesota Epilepsy Group, P.A. Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Minnesota Epilepsy Group, P.A. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 05, 2026, and the notice lists social security numbers and medical records among the information exposed.
The Minnesota Epilepsy Group, P.A. has notified 28 Massachusetts residents that their Social Security numbers and medical records were exposed in a data breach. The filing, submitted to the Massachusetts Office of Consumer Affairs, is dated June 05, 2026.
Your Social Security Number Cannot Be Replaced
If you received a letter from the organisation, your Social Security number is now in the hands of an unknown party and cannot be changed. Unlike a credit card or password, a Social Security number is permanent. It stays with you for life, which is why its exposure creates lifelong risk of identity theft and tax fraud.
Medical records carry their own permanent consequences. They contain highly personal details about diagnoses, treatments, and conditions that can be used for medical identity theft, insurance fraud, or blackmail. Once exposed, there is no way to “recall” this information.
What the Filing Actually Tells Us
The record lists only two categories of exposed information: Social Security numbers and medical records. No passwords were exposed. The filing does not mention any other data fields, nor does it disclose the root cause of the breach, whether the information was copied or simply viewed, or the exact number of Massachusetts residents affected beyond the total of 28 people named in the notice.
Because the filing does not state when the incident occurred, the only reliable way to determine whether your information was included is the notification letter itself. The organisation is required to contact affected individuals directly, usually by post. If you have not received such a letter, it is likely you were not among the 28 people affected. However, if you have moved since the time of the incident, you should contact Minnesota Epilepsy Group, P.A. directly to confirm your status.
The Lifelong Risk of a Stolen Social Security Number
A Social Security number paired with medical records creates a powerful combination for criminals. Fraudsters can use your number to open accounts, file false tax returns, or obtain medical services in your name. Medical identity theft can lead to incorrect information being added to your permanent health record, potentially affecting future care or insurance coverage.
Because these identifiers cannot be reissued like a compromised credit card, the exposure requires ongoing vigilance rather than a one-time fix. The risk does not diminish after a few months; it remains for as long as your Social Security number is valid.
Why Medical Records Matter Long After the Breach
Medical records are among the most sensitive types of personal information. When combined with a Social Security number, they can be used to create convincing false identities for obtaining prescription drugs, filing fraudulent insurance claims, or even securing employment under someone else’s medical history.
Unlike financial account numbers that can be closed, medical histories cannot be reset. The exposure means you must remain alert to unexpected bills, insurance statements, or collection notices that do not belong to you.
How to Protect Yourself Going Forward
Place a freeze on your credit reports with Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name without your explicit permission. A credit freeze is free and does not affect your existing accounts or credit score.
Review every Explanation of Benefits statement from your health insurer carefully. Look for services you did not receive or providers you did not visit. Medical identity theft is often discovered through these documents.
Monitor your tax filings closely each year. If someone attempts to file a return using your Social Security number, the IRS will usually send you a letter. Respond immediately if this occurs.
Consider placing an extended fraud alert on your credit file, which requires creditors to verify your identity before issuing new credit. This provides an extra layer of protection that lasts for seven years.
If you have not yet received a notification letter but believe you may have been treated by Minnesota Epilepsy Group, P.A., contact their privacy office directly to ask whether your records were included in the group of 28 affected individuals.
The breach notice itself does not reveal how the incident happened. What matters now is the information that was exposed and the steps you can still control. Your Social Security number and medical records will require attention for years, not weeks. Starting with a credit freeze and careful monitoring of insurance and tax documents gives you the most practical defense available.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Minnesota Epilepsy Group, P.A..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…