United Underwriters Insurance, a Trucordia Business, is notifying customers of a data breach after an unauthorized actor downloaded files from its systems. The company’s own notice letter leaves the exposed data blank — but a separate Massachusetts regulatory filing confirms Social Security numbers, medical information, financial account information, and driver’s license numbers were all involved.
United Underwriters Insurance, part of Trucordia Insurance Services, LLC (headquartered in Provo, Utah), has begun notifying customers of a security incident involving their personal information. According to the company’s notice letter, it identified suspicious activity on its systems earlier this year and determined, following a forensic investigation, that an unauthorized actor downloaded certain files on May 1, 2026. The underlying breach is dated April 7, 2026 by the company’s own California filing — meaning roughly 143 days passed between the actor’s download of the data and the notice going out to customers on September 21, 2026.
Source: United Underwriters notice letter; California Attorney General data breach report sb24-630066, filed 09/21/2026; Massachusetts OCABR annual data breach report, row 2026-1597, filed 09/22/2026.
What Information Was Exposed
United Underwriters’ own notice letter to customers is a merge-field template that does not spell out what data was involved — it states only that “your [blank] were downloaded by the actor.” A separate filing the company made with Massachusetts regulators, however, is specific: it confirms that Social Security numbers, medical information, financial account information, and driver’s license or state ID numbers were all involved for at least some affected individuals. This is a case where the regulatory filing tells customers more than the notice letter they actually received.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
Why This Matters
The combination of Social Security numbers, driver’s license numbers, financial account information, and medical information is about as serious as a data breach gets — it’s the full toolkit for both financial identity theft and medical identity theft. As an insurance company, United Underwriters holds exactly this kind of sensitive information on its policyholders and applicants as a matter of course.
How Many People Are Affected
United Underwriters has not released a national total. A Massachusetts filing confirms 15 Massachusetts residents were affected — a small state subset that tells us nothing about the size of the breach nationally. Given that United Underwriters is part of a larger, multi-state insurance operation, the true number of affected customers is very likely much larger than the Massachusetts figure alone.
What You Can Do Now
- Enroll in the 24 months of complimentary credit monitoring and identity restoration services offered in United Underwriters’ notice letter before the enrollment deadline
- Place a fraud alert or credit freeze with the three major credit bureaus, given that Social Security numbers were confirmed exposed
- Monitor your financial account statements and explanation-of-benefits notices closely for unauthorized activity
- Watch for phishing attempts referencing United Underwriters, Trucordia, or your insurance policy
- Contact us for a free case review if you received a notice letter from United Underwriters
Do You Have Legal Options?
Insurance companies that collect Social Security numbers, medical information, and financial account details have a legal duty to secure that information. If you received a notice letter from United Underwriters, you may have legal options.
If you received a data breach notice from United Underwriters, contact Emery | Reddy today for a free case review.
FAQ
What information was exposed in the United Underwriters breach?
United Underwriters’ own notice letter does not specify. A separate Massachusetts regulatory filing confirms Social Security numbers, medical information, financial account information, and driver’s license or state ID numbers were involved.
Why doesn’t my notice letter say what information was taken?
The version of the notice letter reviewed for this post is an unpopulated template — the section describing what information was involved was left blank. The confirmed data categories come from a separate filing the company made with Massachusetts regulators, not from the letter itself.
How many people are affected?
United Underwriters has not released a national total. Massachusetts regulators confirm 15 Massachusetts residents were affected, but that is a small state subset of what is likely a much larger breach.
How long did it take United Underwriters to notify customers?
About 143 days passed between the actor downloading data (May 1, 2026) and notice going out to customers (September 21, 2026).
Do I have a legal claim?
Insurance companies have a legal duty to protect the Social Security numbers, medical information, and financial data they collect from customers. If you received a notice letter from United Underwriters, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.