University Surgical Associates Data Breach Investigation
A regulatory listing reports a data incident involving University Surgical Associates, PLLC, a Tennessee healthcare organization, but key details remain unavailable. The reported information potentially includes Social Security numbers and health records, which can create identity-theft and medical-fraud risks. Strauss Borrelli PLLC is investigating the reported incident and the rights of people who may be affected. If you received a notice, use the secure contact form on this page to ask whether you may qualify to pursue a claim.
University Surgical Associates, PLLC is identified in the available incident data as a healthcare organization located in Tennessee. Because healthcare records can contain sensitive identity and medical information, potentially affected individuals should carefully review any notice they receive.
Key Facts at a Glance
- Entity Involved: University Surgical Associates, PLLC (Healthcare)
- Incident Type: Not specified in the available regulatory listing data
- Date of Incident: Not reported in the available materials
- Discovery Date: Not reported in the available materials
- Official Notice Date: Not provided; regulatory data records August 24, 2026 as the public listing date
- Exposed Information: Social Security numbers and health records were reported as potentially involved
- Affected Population: Under investigation or not reported in the available materials
What Happened?
According to structured regulatory listing data, University Surgical Associates, PLLC was associated with a Vermont Attorney General security-breach listing made public on August 24, 2026. The available materials do not identify when the reported event began or ended, when it was discovered, or whether it involved unauthorized access, ransomware, or a third-party service provider. They also do not provide an affected-person count.
The Vermont Attorney General category page is an index of security-breach notices and, by itself, does not supply those missing incident details. Readers should therefore rely on any notice they personally received for account-specific information and avoid assuming that unreported facts have been confirmed. Additional entity-specific filings or notices may eventually clarify the event’s scope, cause, timeline, response measures, and whether particular information was actually accessed or acquired.
What Information Was Exposed?
The incident data identifies Social Security numbers and health records as information that may have been involved. The available materials do not provide a more detailed list of medical, insurance, treatment, prescription, or billing information, so those additional categories should not be assumed.
Social Security numbers may be misused for identity theft, fraudulent accounts, or tax-related fraud. Health information can create separate risks, including medical identity theft, fraudulent patient billing, insurance-verification scams, false prescription inquiries, and phishing messages that impersonate a healthcare provider or insurer. The presence of a data category does not necessarily mean every affected person had that information exposed.
What Should You Do Next?
- Read your notice carefully: Preserve any letter or email you received and compare its description of the affected information with the regulatory summary. Use verified contact information rather than links in unexpected messages.
- Consider a credit freeze or fraud alert: A free credit freeze can make it harder for someone to open new credit in your name. Contact Equifax, Experian, and TransUnion separately to place freezes.
- Review credit and healthcare records: Check your credit reports, medical bills, insurer explanations of benefits, and patient portal activity for unfamiliar accounts, services, prescriptions, or providers.
- Watch for healthcare impersonation scams: Be cautious of callers or messages requesting Social Security numbers, insurance credentials, payments, or portal passwords to “verify” care or resolve a supposed bill.
- Document suspicious activity: Save notices, screenshots, invoices, credit reports, and communications. Report identity theft through IdentityTheft.gov and promptly dispute unauthorized credit, insurance, or medical activity with the appropriate organization.
Your Legal Rights
People affected by a reported data incident may have rights under state privacy, consumer-protection, data-security, or breach-notification laws. The rights available depend on where a person lives, what information was involved, the circumstances of the event, and whether the person experienced losses or other harm.
Potential remedies may include reimbursement for documented expenses, compensation for certain legally recognized harms, or changes to data-security practices, but no outcome can be guaranteed. Deadlines may apply to possible claims. Preserve the notice and records of time spent, fraudulent charges, credit-monitoring costs, medical-billing problems, or other consequences. This general information is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents individuals in privacy and cybersecurity matters and can evaluate the available notices, applicable laws, and documented effects of a reported incident. A confidential case review can help you understand whether you may have a claim, what records should be preserved, and which next steps may be appropriate. Contacting counsel does not guarantee that a claim exists or that compensation will be recovered.
If you received a breach notification letter from University Surgical Associates:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










