Terry J. Dubrow Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Terry J. Dubrow notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on August 13, 2026, and the notice lists social security numbers, government id numbers, health records among the information exposed.
The filing from Terry J. Dubrow, reported to the Vermont Attorney General on August 13, 2026, states that the personal information of two people was exposed. The categories listed are Social Security Numbers, Government ID Numbers, and Health Records.
A Social Security Number Does Not Expire
If you received a notification letter, this exposure creates a permanent risk that cannot be undone by a simple password change or account update. A Social Security Number cannot be reissued on request the way a credit card or password can. Once it is out, it remains usable for identity theft, tax fraud, or fraudulent medical claims for the rest of your life.
The same filing lists Government ID Numbers and Health Records alongside the Social Security Numbers. Health Records in particular can be paired with an SSN to create highly convincing fraudulent insurance claims or to impersonate you when seeking care. These two categories together have lasting value to fraudsters because neither loses its sensitivity over time.
What the Record Does and Does Not Tell Us
The Vermont filing establishes that two individuals had their records included in an incident. It does not disclose how the breach occurred, whether it involved an intrusion, a misconfiguration, or any other cause. No passwords were exposed. The record contains no credential data, so there is no need to change any password connected to this provider.
Because the filing lists only these three categories, you can be certain that no other types of information—such as financial account numbers—are stated as exposed. That absence is meaningful. It narrows the specific risks you need to focus on.
How to Determine Whether This Affects You
The organisation is required to notify affected individuals directly, usually by post. If you have not received a letter, it is likely that your records were not among the two included in this filing. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact Terry J. Dubrow directly to confirm whether their information was involved.
The Permanent Nature of These Records
Unlike a credit card that can be cancelled and reissued, a Social Security Number and the linked health history stay with you forever. This is why regulators treat SSN exposures differently from other data breaches. The two people named in this filing now carry an elevated risk that fraudsters could use their Government ID Numbers and Health Records to open accounts, file false tax returns, or submit medical claims in their names.
Health Records add another layer. Once paired with an SSN or Government ID, they can be used to request prescription drugs, schedule procedures, or commit insurance fraud that may later appear on your own medical history. The combination is particularly valuable because it is difficult for an individual to monitor every possible misuse.
What Remains Under Your Control
Even with this exposure, you still have practical ways to reduce the harm. The key is focusing on the specific categories listed rather than treating this as a generic data breach. Because no passwords were exposed, the incident does not put any online account at direct risk of takeover. That is genuinely good news in an otherwise serious situation.
The small number of people affected—exactly two—suggests this was a narrowly targeted or limited incident rather than a mass exposure. Still, for those two individuals the consequences are permanent.
Placing This Filing in Context
This notice reached the Vermont Attorney General on August 13, 2026. The record does not state when the incident itself occurred, so the only reliable way to know if you are affected remains the direct notification from the organisation. The same provider also filed a notice in California, confirming the event is not limited to Vermont residents.
Because Social Security Numbers and health records never age out of usefulness to identity thieves, this is the type of breach that requires long-term vigilance rather than a one-time response. The absence of any password data means you do not need to spend time rotating credentials for this provider. Your effort is better spent on the exposures that cannot be changed.
Concrete Steps That Match This Exposure
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This is the single most effective way to stop new accounts from being opened with your Social Security Number.
- Review every Explanation of Benefits statement from your health insurer. Look for claims you did not make or services you did not receive. Report anything suspicious immediately.
- File your taxes early each year. This reduces the window in which someone else could file a fraudulent return using your SSN.
- Monitor your medical records through every provider you use. Request a full record once per year and check for unfamiliar entries.
- Contact Terry J. Dubrow directly if you have moved in recent years and have not received a letter. Confirm whether your specific records were part of the two affected.
The filing is narrow but the categories involved are among the most serious. By focusing only on what the Vermont record actually states—two people, three permanent categories, no passwords—you can direct your energy where it is needed instead of reacting to risks that do not apply here.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Terry J. Dubrow.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…