Skip to content
Back to Blog
high severity July 17, 2026 · 5 min read

ZenPatient, Inc. Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

ZenPatient, Inc. notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 17, 2026, and the notice lists name, full date of birth, passport number and medical information among the information exposed. The filing puts the incident itself on December 05, 2025.

ZenPatient, Inc. Data Breach Notice (Washington Attorney General)

The filing from ZenPatient, Inc. means that 651 Washington residents now face a permanent mix of identity and health risks that cannot be undone. Your name, full date of birth, passport number, and medical information were listed in the incident that occurred on December 05, 2025. The organisation filed the notice with the Washington Attorney General on July 17, 2026 — 224 days later.

Why the 224-day gap stands out

Seven and a half months passed between the breach date and the official filing. State notification rules allow time for investigation, but an interval this long is unusual and gives anyone whose records were taken a long period during which they had no way of knowing their information was exposed. The record does not explain what happened inside that window.

What each exposed category actually enables

Name combined with full date of birth creates a reliable anchor for identity thieves. A date of birth never expires and cannot be reissued. When paired with a passport number, it becomes strong evidence of identity for opening accounts, applying for credit, or requesting government services in your name.

Passport numbers are particularly valuable because they are government-issued travel documents. Replacing one is expensive, requires in-person appointments, and can take weeks. Until a new passport is issued, the old number remains usable for fraud.

Medical information adds another permanent layer. It can be used for insurance fraud, to file false claims in your name, or to impersonate you when seeking prescription drugs or care. Health records also make targeted social engineering far more convincing — a scammer who knows your medical history sounds legitimate.

No passwords or login credentials were exposed in this incident. That is genuinely good news. You do not need to change any ZenPatient password, and your account itself is not at direct risk of takeover from this breach.

The records that cannot be changed

Full date of birth and passport number belong to the category of information that stays sensitive for life. You cannot get a new birthday. A new passport replaces the number eventually, but the old one can still be abused during the gap. Medical details tied to your name and date of birth also cannot be reset. These three facts together create a durable identity profile that criminals value years after the breach.

The filing lists these categories for the incident as a whole. Not every one of the 651 people necessarily had every field taken. Your own notification letter is the only document that confirms exactly which details applied to you.

How to determine whether this concerns you

ZenPatient, Inc. is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of the 651 affected. However, if you have moved since December 05, 2025, or changed addresses at any point after the incident, write or call ZenPatient directly to confirm whether you were included. Absence of a letter is usually meaningful, but only the organisation can give you a definitive answer.

What the combination of passport and medical data changes for you long-term

Most people think of identity theft as credit-card fraud that can be cleaned up in weeks. This mix is different. A passport number plus medical records lets someone impersonate you with doctors, insurers, and government agencies in ways that are harder to detect and fix. Future loan applications, employment background checks, or insurance underwriting could be affected if fraudulent activity is attached to your details.

Because medical information was exposed, you should watch Explanation of Benefits statements from every health insurer you use. Look for claims you did not file or treatment you did not receive. Early detection is the only practical defense once the data is out.

The limits of what this filing tells us

The record does not disclose how the breach occurred, whether it involved an external attacker, a misconfiguration, or an insider. It does not state whether the data was stolen, accidentally published, or accessed in some other way. It also does not specify how many of the 651 people were Washington residents versus patients from other states. All of those details remain unknown to the public.

What is certain is that 651 people had the combination of name, full date of birth, passport number, and medical information placed at risk on December 05, 2025, and the public only learned of it more than seven months afterward.

Practical steps that address this specific exposure

  • Request your free credit reports from Equifax, Experian, and TransUnion now and again every four months. Look for accounts or inquiries you do not recognise. A passport number can be used to open new credit in your name.
  • Place a fraud alert or credit freeze with the three major bureaus. A freeze stops new credit from being opened without your direct approval and is the strongest control available when government identifiers are exposed.
  • Review every Explanation of Benefits from your health insurance carriers. Flag any service or prescription you did not receive. Medical identity theft often shows up here first.
  • Monitor your passport status through the State Department if you hold a U.S. passport. Be wary of any unexpected mail or calls claiming passport problems.
  • Keep records of this incident. Save the notification letter and a copy of this filing. If fraud appears later, these documents help prove when the breach occurred and which data was involved.

The exposure cannot be undone, but early vigilance on credit, insurance claims, and government documents gives you the best chance of catching misuse before it causes lasting damage. The 224-day delay between the December 05, 2025 incident and the July 17, 2026 filing simply lengthens the window during which you must stay alert.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on ZenPatient, Inc..

  1. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  2. Report the passport number. A compromised passport number can be reported to the US State Department, which will flag it. Replacing it is neither quick nor free, so report it before you need to travel.
  3. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity High
Disclosed July 17, 2026
Last reviewed July 22, 2026
Affected 651
Data exposed NameFull Date of BirthPassport NumberMedical Information
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email