Call-on-Doc Data Breach Exposes Sensitive PHI and PII

Published
September 22, 2026
Updated
September 22, 2026
Call-on-Doc Data Breach Exposes Sensitive PHI and PII
Call-On-Doc

Call-on-Doc, a web-based telehealth platform based in Dallas, Texas, experienced a data breach between late December 2025 and early January 2026.

An unauthorized party gained access to Call-on-Doc's network between Dec. 22, 2025, and Jan. 3, 2026.

On Jan. 22, 2026, a threat actor using the name "iProfessor" posted on the open web claiming to be selling a database from Call-on-Doc. The threat actor alleged that the dataset contained 1,144,223 patient records tied to a breach dated December 2025. The data allegedly included patient names, contact details, addresses, medical categories and conditions, prescribed services, transaction numbers and payment amounts.

On Aug. 19, 2026, the company's investigation determined that protected health information had been potentially accessed or acquired by the unauthorized party during that window. These included patients' names, email addresses, physical addresses, phone numbers, medical diagnoses, medication information and visit types.

The incident has so far impacted 92,012 Texas residents.

The company disclosed the incident to the California Attorney General, as well as posted a notice on its website. The company began notifying affected consumers on Sept. 18, 2026, by U.S. Mail.

Call-on-Doc's response to the breach

The company recommended that consumers take precautionary measures to protect their personal and medical information. These recommendations included monitoring credit files and reviewing medical-related documents for signs of potential misuse.

The notification letter to affected individuals provided contact information for the three major credit reporting agencies as well as information about resources available through the Federal Trade Commission.

Call-on-Doc set up a dedicated call center for individuals with questions about the incident. According to the notification letter, the response line is available for 90 days from the date of the letter, between 8 a.m. and 8 p.m. Eastern time, Monday through Friday, excluding holidays.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Call-On-Doc
Consumers Notification date
Date of Breach
December 22, 2025; January 3, 2026
Breach Discovered Date
Total People Affected
Information Types Exposed
  • patients' name
  • email address
  • physical address
  • phone number
  • medical diagnosis
  • medication information
  • visit type
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image