Modjarrad & Associates, PC d/b/a MAS Law Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Modjarrad & Associates, PC d/b/a MAS Law notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 21, 2026, and the notice lists social security numbers, medical records and driver's license numbers among the information exposed.
The exposure of your Social Security number in this incident cannot be undone. That single piece of information, paired with a driver’s license number or medical record, gives someone the permanent keys to open accounts, file taxes, or build synthetic identities in your name. Modjarrad & Associates, PC d/b/a MAS Law reported the breach to Massachusetts authorities on May 21, 2026, affecting two people. The filing lists Social Security numbers, driver’s license numbers, and medical records as the categories involved.
A Social Security Number Is Permanent
Unlike a credit card or password, a Social Security number cannot be replaced at will. Once it is out of the organisation’s control, it remains valuable to fraudsters for the rest of your life. The same is true of the driver’s license numbers listed in the filing. Medical records add another permanent layer: they can be used to file false insurance claims or to impersonate you in healthcare settings. These three categories together create a high-quality identity package that does not expire.
No passwords were exposed. That is genuine good news. You do not need to change any login credentials because of this specific incident. The risk lies entirely in the non-revocable identifiers and the sensitive health information now outside the firm’s systems.
What the Two-Person Scale Actually Means
The filing states that exactly two Massachusetts residents were affected. This is an unusually small number for a public breach notice, yet the categories exposed are among the most sensitive possible. When a law firm holds medical records alongside government identifiers, even a handful of people represents a serious compromise for those individuals. The small headcount does not reduce the weight of what was lost; it simply limits how many letters the organisation was required to send.
How to Determine Whether This Filing Concerns You
The organisation is required to notify affected individuals directly, usually by post. If you receive a letter from Modjarrad & Associates or MAS Law, treat the contents as the definitive statement of what records of yours were included. Absence of a letter usually indicates you were not in the affected group. Anyone who has moved since the incident should contact the firm directly to confirm their status, because mail sent to an old address may never arrive.
The record does not state when the incident itself occurred, only the filing date of May 21, 2026. Without an incident date, the letter remains the only practical way to know whether your information was involved.
Why Medical Records Raise the Stakes
Medical records are not just private history. When combined with a Social Security number they allow fraudsters to create convincing medical identities, rack up bills in your name, or tamper with insurance claims. Insurers and providers rely on these records to verify identity; once the data is loose, verification becomes harder for the legitimate owner. The filing’s inclusion of medical records alongside government IDs means the breach carries both financial-fraud risk and long-term healthcare-fraud risk.
The Identity Theft Window Never Closes
Because Social Security numbers cannot be reissued on demand, the exposure creates an open-ended threat. Criminals can wait months or years before using the data. A driver’s license number makes the package more credible for in-person fraud or government-service impersonation. The combination is particularly useful for synthetic identity fraud, where real pieces of different victims’ information are stitched together to create an entirely new, usable person.
This is not theoretical. A Social Security number paired with a driver’s license is precisely the foundation synthetic-identity schemes are built on. Medical details simply make the synthetic file more believable to insurers and credit agencies.
What Remains Under Your Control
You cannot retract the data, but you can limit what criminals do with it. Monitoring is the realistic response when permanent identifiers are lost. Place a freeze with the three major credit bureaus so new accounts cannot be opened without your explicit permission. Review every Explanation of Benefits statement from your health insurer; fraudulent claims often appear there first. Request your annual tax transcript from the IRS to catch any returns filed under your number.
These steps do not erase the breach. They narrow the practical ways the exposed information can be turned against you.
The Limits of What This Filing Tells Us
The Massachusetts notice establishes only that the breach happened, that two residents were affected, and which categories of information were listed. It does not disclose the root cause, whether data was copied or simply viewed, or how long any exposure lasted. Those details remain unknown to the public. Speculation beyond the record serves no one; the concrete facts are serious enough on their own.
For the two people named in this filing, the exposure of non-revocable identifiers alongside medical records creates a lifelong monitoring obligation rather than a one-time problem to solve and forget. The rest of us simply note that even a two-person breach can involve the exact data types that hurt most when lost.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Modjarrad & Associates, PC d/b/a MAS.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Clinical Associates of the Finger Lakes (CAFL) Listed by Barracuda Ransomware Group
The company mishandled its clients' and employees' data, which is why it was leaked. We extracted al…
Black Cat Engineering & Construction WLL Listed by Qilin Ransomware Group
Civil Engineering Construction…
Instituto Ferrero de Neurología y Sueño Listed by kazu Ransomware Group
Instituto Ferrero de Neurología y Sueño (IFN) is a specialized medical center in Argentina that focu…