Three Oaks Hospice Data Breach Investigation
Three Oaks Hospice Inc reported unauthorized activity in its email environment that may have involved personal, medical, and health insurance information. The incident may affect patients, caregivers, employees, or other individuals whose information was maintained in company email. Strauss Borrelli PLLC is investigating the reported Three Oaks Hospice data incident and the rights of affected individuals. If you received a notice, use the secure contact form on this page to ask whether you may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: Three Oaks Hospice Inc (Healthcare)
- Incident Type: Unauthorized email activity classified in structured Texas Attorney General filing data as a Hacking/IT Incident
- Date of Incident: August 8, 2025; no incident end date was disclosed
- Discovery Date: August 8, 2025
- Official Notice Date: August 17, 2026 for affected affiliated hospices; a public announcement was posted September 17, 2026
- Exposed Information: Names, dates of birth, driver’s license numbers, Social Security numbers, medical information, and health insurance information may have been involved
- Affected Population: 17,856 individuals, as reported in structured Texas Attorney General filing data; the company’s public notice does not state a total
What Happened?
According to its public data incident notice, Three Oaks Hospice discovered unauthorized activity associated with its email environment on August 8, 2025. The company reported taking immediate steps to investigate, contain, and remediate the issue. Following an extended review, Three Oaks Hospice determined on July 20, 2026, that the unauthorized email activity affected personal information.
The company stated that it notified affected affiliated hospices on August 17, 2026, and later posted a public announcement on September 17. Three Oaks Hospice described securing its network and safely restoring its systems and operations. It also stated that it was unaware of actual or attempted misuse of the information involved. That statement is reassuring, but it does not eliminate the possibility of future identity theft, healthcare fraud, or targeted phishing. The notice does not identify how the unauthorized party obtained access to the email environment or specify how long access may have continued.
What Information Was Exposed?
Three Oaks Hospice reported that the information potentially involved may have included names, dates of birth, driver’s license numbers, Social Security numbers, medical information, and health insurance information. The company emphasized that not every data element was present for every affected person.
This combination of identity and healthcare data can create risks beyond ordinary financial fraud. Criminals may attempt medical identity theft, fraudulent patient billing, false insurance claims, insurance-verification scams, or deceptive prescription inquiries. Information from the incident could also be used to make phishing calls, emails, or text messages appear credible.
What Should You Do Next?
- Review and preserve your notice: Keep the letter, envelope, and related emails. Determine which information Three Oaks Hospice says may have been involved and retain the documents in case you later notice suspicious activity.
- Protect your credit files: Consider placing a free credit freeze or fraud alert with the three major credit bureaus. Review your credit reports for unfamiliar accounts, address changes, or credit inquiries.
- Monitor healthcare records: Check insurance explanations of benefits, patient portals, prescription histories, and medical bills for services you did not receive. Promptly dispute unfamiliar providers, procedures, or insurance claims.
- Be cautious about healthcare scams: Do not provide passwords, Social Security numbers, insurance identifiers, or payment information in response to unsolicited billing, prescription, or insurance-verification messages. Contact the provider or insurer through a verified number.
- Document and report suspicious activity: Save fraudulent messages, record disputed charges, and contact the appropriate provider, insurer, financial institution, or identity-theft reporting service. Questions about the company’s notice may be directed to its listed call center at 1-800-610-8565.
Your Legal Rights
People affected by a healthcare data incident may have rights under applicable state privacy, consumer-protection, data-breach notification, or other laws. The available options depend on where the person lives, what information was involved, whether adequate safeguards and notice were provided, and whether the incident caused losses or other harm.
Receiving a notice does not automatically establish a legal claim, and the absence of known misuse does not necessarily resolve every legal issue. Potentially affected individuals should preserve the notice, records of protective expenses, time spent responding, fraudulent communications, disputed bills, and evidence of identity or medical fraud. An attorney can evaluate those circumstances and applicable deadlines. This general information is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
The firm evaluates cybersecurity and privacy incidents involving sensitive personal and healthcare information. Its attorneys can review the available notices, assess the categories of information potentially involved, explain applicable legal options, and evaluate whether an affected individual may qualify to pursue a claim. Contacting counsel does not guarantee a particular outcome, but it can help consumers understand relevant rights and deadlines.
If you received a breach notification letter from Three Oaks Hospice Inc:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










