Tri-Cities Gastroenterology Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Tri-Cities Gastroenterology notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on April 29, 2026, and the notice lists social security numbers, health records among the information exposed.
The filing from Tri-Cities Gastroenterology, reported to the Vermont Attorney General on April 29, 2026, states that the personal information of one Vermont resident was exposed. The exposed categories named in the record are Social Security Numbers and health records.
A Social Security Number Cannot Be Replaced
If you received a notification letter from Tri-Cities Gastroenterology, that letter is the only reliable way to confirm whether your Social Security number was included. The organisation is required to notify affected individuals directly, usually by post. Absence of a letter usually means you were not in the affected group, but anyone who has moved since the incident should contact the practice directly to confirm their status.
A Social Security number does not expire and cannot be reissued on request the way a credit card or password can. Once it is exposed, it remains a permanent identifier that can be used to open accounts, file fraudulent tax returns, or apply for government benefits in your name. This risk does not diminish after a few months or a few years. It is lifelong.
Health Records Carry Permanent Sensitivity
The filing also lists health records as exposed. These documents can contain diagnoses, treatment details, medications, and other clinical information that is protected under federal privacy rules. Unlike a credit card number, medical history cannot be cancelled or reissued. It can be used for insurance fraud, prescription fraud, or to impersonate you when seeking care.
Because the record names both Social Security numbers and health records, the combination creates a high-value target for identity thieves. An attacker who has both can more easily link records across systems, answer knowledge-based security questions, or build a convincing synthetic identity.
What the Single-Person Scope Actually Means
The notice covers exactly one person. That small number does not reduce the seriousness for the individual affected. It does mean the breach was narrowly targeted or limited in discovery. The filing does not disclose the initial access vector, whether the data was copied or simply viewed, or whether any encryption was in place. Those details remain unknown.
No passwords were exposed. This is genuinely good news. You do not need to change any password for Tri-Cities Gastroenterology, and there is no credential-related risk from this incident that requires immediate rotation.
The Lifelong Nature of These Two Data Types
Most breach coverage focuses on immediate risks such as credit card charges. Those risks exist here and should be monitored, but the deeper problem is permanence. A stolen Social Security number stays valid for decades. Health records retain their value to fraudsters for just as long. Credit freezes, monitoring services, and fraud alerts are temporary tools layered on top of data that cannot be changed.
If your information was included, the exposure creates a permanent increase in your identity theft risk profile. The practical response is to treat this Social Security number as permanently public and build defenses around that reality rather than hoping the data stays private.
Why Health Records Amplify the Risk
Health records often include dates of birth, addresses, policy numbers, and clinical notes that can be cross-referenced with the Social Security number. This combination makes it easier for someone to impersonate you at other medical providers, file false claims, or obtain prescription medications. It also raises the possibility of medical identity theft that can corrupt your actual health record with incorrect information.
The record does not state that every category applied to the single affected person, only that these categories were involved in the incident. Your notification letter will specify exactly what was exposed in your case.
Concrete Protections That Address This Exposure
Place a freeze on your credit files at the three major bureaus. This prevents new accounts from being opened in your name even if someone has your Social Security number. The freeze is free, reversible when you need to apply for credit, and far more effective than monitoring alone.
Review every Explanation of Benefits statement from your health insurer. Look for services you did not receive. Medical identity theft is often discovered only when someone else’s treatment appears on your insurance record. Report discrepancies to your insurer immediately.
File your taxes early each year. This reduces the window in which someone else can file a fraudulent return using your Social Security number. If you receive a notice from the IRS that a return has already been filed under your number, act quickly.
Consider placing an extended fraud alert or requesting a credit report review with the Social Security Administration if you suspect misuse of your number for benefits claims. These steps do not remove the number from circulation, but they create friction for anyone trying to use it.
Keep records of the notification letter and the date you received it. If identity theft occurs later, documentation showing when you first learned of the exposure helps establish timelines with banks, insurers, and government agencies.
The filing does not state when the incident occurred, only the April 29, 2026 filing date with the Vermont Attorney General. The letter you may have received remains the primary way to determine whether you were affected. If you have any connection to Tri-Cities Gastroenterology as a patient, contact their privacy office directly if you have not received correspondence. They are required to provide confirmation and additional guidance when asked.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Tri-Cities Gastroenterology.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…