McEwen & Associates, a Texas-based medical practice support company that provides billing and management services to medical groups, experienced a major data breach. The breach was disclosed to the U.S. Department of Health and Human Services on Aug. 21, 2025, reported as a hacking incident.
The cybersecurity incident compromised both personally identifiable information (PII) and protected health information (PHI). The total number of affected individuals has not been released, but may include thousands of patients from hundreds of medical practices and facilities.
Exposed information may include names, addresses, dates of birth, Social Security numbers, medical records, health insurance details and payment information. The combination of the different types of personal and health data increases the risk of identity theft and medical fraud for impacted individuals.
In addition to required state and federal disclosures, McEwen & Associates will work with its medical practice clients to identify impacted individuals and notify them by mail.
If you believe your personal information may have been compromised in this breach:
For more details about the company’s services and background, visit the McEwen & Associates website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.