Terry J. Dubrow Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Terry J. Dubrow notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 13, 2026, and the notice lists social security numbers, medical records and driver's license numbers among the information exposed.
The filing from Terry J. Dubrow, reported to the Massachusetts Attorney General on August 13, 2026, states that information belonging to 45 people was exposed. The categories listed are Social Security numbers, medical records, and driver’s license numbers.
Social Security numbers cannot be replaced
If your Social Security number was among the records included, it remains permanently tied to you. Unlike a credit card or password, it cannot be reissued on request. That single number, paired with a driver’s license number from the same filing, gives someone the core building blocks needed to open accounts, file fraudulent tax returns, or create synthetic identities that can persist for years.
Medical records listed in the filing add another permanent dimension. They can be used to file false insurance claims, obtain prescription drugs in your name, or blackmail you with sensitive health details. Once those records leave the organisation’s control, you cannot revoke them.
No passwords or login credentials were exposed
The filing does not list passwords, and the record establishes that credential exposure did not occur. This is genuinely good news. You do not need to change any password connected to this provider because none was included in the exposed data. That particular risk simply does not apply here.
What the 45-person scale actually tells you
The number of affected individuals is small and precise. The filing names exactly 45 Massachusetts residents. This is not a mass breach affecting hundreds of thousands; it is a narrowly defined incident that still carries high individual risk precisely because the data involved is so sensitive and cannot be changed.
How to determine whether this filing includes you
The organisation is required to notify affected individuals directly, usually by post. If you have not received a letter, it is likely your information was not included. However, because the filing does not state when the incident occurred, anyone who has moved since receiving care from this provider should contact Terry J. Dubrow directly to confirm whether their records were part of the 45 named in the Massachusetts notification.
The lifelong value of these specific records
A Social Security number retains its value to identity thieves for decades. Medical records never expire. A driver’s license number can be used to impersonate you when opening new lines of credit or applying for government benefits. Because the filing lists all three together, the combination creates stronger fraud potential than any one piece alone.
Medical information in particular can affect insurance premiums, employment background checks, or even personal relationships if it falls into the wrong hands. These are not theoretical risks; they are the exact reasons these categories trigger mandatory notification under Massachusetts law.
The letter remains the only reliable check available
Absence of a letter usually means you were not in the affected group of 45. Letters can be delayed or misdelivered, however, so if you have any relationship with this provider and have changed addresses in recent years, the safest step is to reach out and ask. The filing itself gives no discovery date and no separate incident date, so the letter is the only practical indicator the record provides.
What this exposure enables
With a Social Security number and driver’s license number, a criminal can attempt to:
- File taxes under your name and divert refunds
- Open credit accounts that appear legitimate
- Apply for government benefits using your identity
- Build a synthetic identity by mixing your details with fabricated ones
The addition of medical records increases the chance of insurance fraud or targeted phishing that references your actual health history, making the scam more convincing.
Concrete differences between permanent and replaceable data
Most data-breach advice assumes everything can be fixed by changing a password or canceling a card. That does not apply here. The Social Security number and medical records listed in this filing will remain yours for life. The only realistic protection is vigilance: monitoring for misuse rather than hoping the data can be made safe again.
Driver’s license numbers can sometimes be replaced by obtaining a new license, but the Social Security number cannot. This imbalance is why the filing triggers formal notification requirements and why the 45 affected individuals face elevated long-term risk.
Focus on what you can still control
While you cannot change your Social Security number, you retain control over how closely you monitor the accounts and records tied to it. Early detection remains the most effective defense when permanent identifiers are exposed. The small number of people involved means the organisation should be able to reach each person directly, but the lifelong sensitivity of the data means your own follow-up matters even after any letter arrives.
The record contains no information about the root cause, whether the data was taken by an outsider or someone with internal access, or how long the exposure existed. Those details are not disclosed. What is disclosed is that these three categories belonging to 45 Massachusetts residents are now outside the organisation’s control, and two of them cannot be changed.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Terry J. Dubrow.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…