All Breaches
January 27, 2025 Verified Sensitive Record Healthcare

Visiting Nurse Association of Texas 2025 Data Breach

The Visiting Nurse Association of Texas 2025 data breach was a confirmed cybersecurity event involving personal and health information held by the Dallas-based nonprofit healthcare and community-services organization. The Texas Attorney General records the breach period as January 27 through July 18, 2025 and the discovery date as July 17, 2025.

Current Texas Attorney General record BR-0005191 reports that 28,467 people across the United States were affected, including 14,798 Texas residents. The organization's January 2026 consumer letter separately confirms person-specific data fields and 24 months of credit monitoring offered to affected people.

How Was the VNA Texas Breach Confirmed?

The primary count source is Texas Attorney General data security breach record BR-0005191. It identifies Visiting Nurse Association of Texas at its Dallas address and publishes separate fields for the incident start and end, discovery date, nationwide total, Texas subset, information categories, and notification methods.

Consumer letter 2026-148 in Massachusetts' official archive was issued on behalf of Visiting Nurse Association on January 30, 2026. It confirms that health and identity information may have been involved, says there was no evidence of misuse, and describes protection through Cyberscout. ClaimDepot connects the Texas and Massachusetts records to the same incident.

What Happened From January 27 Through July 18, 2025?

The Texas regulatory record says the event began on January 27, 2025 and ended on July 18, with discovery on July 17. An incident period extending one day beyond discovery may reflect access being ended during response, but the public sources do not explain the technical reason for this date relationship.

The notices do not disclose how the actor entered the environment, which servers or applications were involved, whether malware was used, whether a ransom demand was made, or the identity of the actor. This record therefore relies only on the official date range and confirmed data categories and does not attribute the event to a particular threat actor or technique.

What Identity Information Was Affected?

The Texas Attorney General lists names, Social security numbers, driver's license numbers, government-issued identification such as passport or state ID numbers, and dates of birth among the principal affected categories. The scope varied by individual, so the complete set should not be assumed for every person.

The Massachusetts consumer letter separately says a recipient's name could be at risk together with a date of birth and Social Security number. That combination raises the risk of new-account fraud, tax-identity misuse, and targeted social engineering. The person-specific fields in an individual's notice provide the most accurate description of that recipient's exposure.

What Health Information Was Affected?

Official sources confirm the broad categories of medical information and health-insurance information. The Massachusetts letter lists medical-record number, mental or physical condition, diagnosis, diagnosis code, treatment location, provider name, admission date, prescription information, subscriber member number, and client ID number among possible fields.

These health fields can create risks of fraudulent healthcare claims, medical-identity misuse, and targeted scams built around real care details. The sources do not say every person had the same health fields involved. Payment cards, bank accounts, passwords, and email contents have not been added as confirmed categories for this event.

How Many People Were Affected and How Was Notice Provided?

Texas Attorney General record BR-0005191 publishes an exact nationwide total of 28,467 people and a Texas subset of 14,798. The Texas figure is included in the nationwide population and has not been added on top of it. ClaimDepot's 14,798-person headline likewise refers to Texas residents rather than the U.S. total.

According to the Texas record, consumers were notified by U.S. mail, print-media publication, and a posting on a company or special website. The Massachusetts letter is dated January 30, 2026. The later publication date shown in the Texas portal reflects a regulatory-record update or public posting and does not represent a second incident.

What Should Affected People Do?

The Massachusetts letter says affected people were offered 24 months of single-bureau credit monitoring, a credit report, and a credit score through Cyberscout, a TransUnion company. Recipients should enroll only with the code in their authentic letter and review credit reports, bank activity, insurance explanations of benefits, and medical-service records for unfamiliar transactions or services.

When a Social Security number was involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate. Identification numbers, passwords, payments, or verification codes should not be shared through unexpected messages claiming to represent VNA, Cyberscout, a health plan, or a provider. The incident assistance line in the official letter is 1-844-784-5324.

28.5 Thousand
Affected Accounts
19
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

19
Personal information
Protected health information
Names
Social security numbers
Driver’s license numbers
Government-issued identification numbers
Dates of birth
Medical information
Health insurance information
Medical record numbers
Mental or physical conditions
Diagnoses
Diagnosis codes
Treatment locations
Provider names
Admission dates
Prescription information
Subscriber member numbers
Client identification numbers

Additional Information

Added DateJuly 27, 2026
Breach DateJanuary 27, 2025
Domainvnatexas.org
SourceTexas Attorney General and Massachusetts official notice confirming dates, nationwide count, identity fields, and protected health information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information