Skip to main content
Jump to a category page

Texas Spine Consultants, an Addison spine-surgery practice, has confirmed a data breach affecting at least 96,234 Texas patients — its second reported breach in about two years, and by far its largest.

Texas Spine Consultants, PLLC, a spine-surgery practice based in Addison, Texas, reported a data breach to the Texas Attorney General on September 15, 2026, confirming 96,234 affected Texas residents — the single largest Texas breach figure of the week. The practice separately reported the incident to the Vermont Attorney General’s Office on September 14, 2026, covering 2 Vermont residents, which confirms the breach reaches beyond Texas, though no national total has been published.

Source: Texas Attorney General Data Security Breach Report, filing published 09/15/2026 (96,234 Texas residents); Vermont Attorney General’s Office security breach notice table, reported 09/14/2026 (2 Vermont residents).

What Information Was Exposed?

According to Texas Spine Consultants’ own filings, confirmed independently on both the Texas and Vermont regulator records, the exposed information includes:

  • Full name
  • Address
  • Social Security number
  • Medical information / health records
  • Date of birth

This Isn’t Texas Spine Consultants’ First Breach

Texas Spine Consultants previously disclosed a separate data breach in 2024, after an employee email account was compromised in May of that year. That earlier incident affected 8,048 individuals and exposed patient names, Social Security numbers, and other sensitive information. This new breach, confirmed in September 2026, is a distinct and far larger incident — more than ten times the size of the 2024 breach by confirmed population.

Source: Public reporting on Texas Spine Consultants’ 2024 breach notification, dated 10/17/2024; this earlier incident is separate from, and not the subject of, the new September 2026 breach described above.

No Timeline Published Yet

Neither the Texas nor the Vermont filing discloses when Texas Spine Consultants first detected the intrusion or when its investigation concluded. Without those dates, it isn’t yet possible to say how quickly the practice responded once it learned of the breach. Texas Spine Consultants’ own notice letter, once available, should supply that timeline.

Notice Went Out Multiple Ways

The Texas filing records that notice was provided to consumers by mail, website posting, and print publication. Using more than one method, including publication, often signals that the practice didn’t have current contact information for everyone affected — meaning some patients may not have received a direct letter.

Do You Have Legal Options?

Healthcare providers that collect and store Social Security numbers and medical records have a legal duty to secure that information and to notify patients without unreasonable delay.

If you’re a current or former patient of Texas Spine Consultants, contact Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

FAQ

Who is affected by the Texas Spine Consultants data breach?

Texas Spine Consultants confirmed 96,234 affected Texas residents in its filing with the Texas Attorney General, plus a small number of Vermont residents in a separate filing. A national total has not been disclosed.

What information was exposed?

According to the practice’s own regulator filings, the exposed data includes names, addresses, Social Security numbers, medical information and health records, and dates of birth.

Is this the same breach Texas Spine Consultants had before?

No. Texas Spine Consultants disclosed a separate, smaller breach in 2024 that affected 8,048 individuals after an employee email account was compromised. This new breach, confirmed in September 2026, is a distinct incident affecting a much larger group of patients.

I never got a letter. Could I still be affected?

Possibly. The Texas filing states that notice was provided by mail, website posting, and print publication — a combination companies often use when they don’t have current addresses for everyone affected.

Do I have a legal claim?

Healthcare providers that collect and store Social Security numbers and medical records have a legal duty to secure that information and to notify patients without unreasonable delay. If you’re a current or former patient of Texas Spine Consultants, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now