Over 900,000 Americans just had their personal and health info exposed in medical data breach — names, phone numbers, treatments and SSNs

Image of man on computer with data security ecosystem
(Image credit: Getty Images)

Getting in to see your doctor in person can be difficult, especially when you’re busy. This is why many Americans have turned to telehealth instead. However, one such service has reported that it fell victim to a data breach in which the personal and medical info of more than 900,000 patients was exposed online.

As reported by BleepingComputer, the service in question is ConnectOnCall, and it’s a subsidiary of the healthcare software as a service company Phreesia. In addition to telehealth, ConnectOnCall provides after-hours on-call answering services for doctor’s offices, hospitals and other healthcare businesses.

Now, though, ConnectOnCall has revealed that between February and May of this year, a third party had access to its service, app data, and some provider-patient communications.

Here’s everything you need to know about this latest medical data breach — the third one I’ve covered this month — along with some tips and tricks on what steps you can take to stay safe from hackers following a security incident like this one.

What data was exposed

A data breach warning notification on a laptop

(Image credit: Shutterstock)

In a press release detailing what occurred, ConnectOne explains that after discovering a breach had taken place, it immediately began an internal investigation and sought the help of external cybersecurity specialists to “determine the full nature and scope of the incident.”

As for how many Americans are caught up in this data breach, the company told the U.S. Department of Health and Human Services that approximately 914,138 patients were affected. The personal information exposed during the almost three-month period in which its systems were accessed includes medical record numbers, dates of birth and info related to health conditions, treatments or prescriptions.

Unfortunately though, in a small number of cases, affected individuals also had their Social Security numbers accessed by this unauthorized third party. At this time, we still don’t know if a single individual or a group of hackers was behind the breach itself.

As for ConnectOnCall’s parent company Phreesia, it assured customers that its services, as well as its patient intake platform, were not affected by this attack.

How to stay safe after a data breach

A woman looking at a smartphone while using a laptop

(Image credit: Shutterstock)

Although I haven’t been able to track down the data breach notification letter from ConnectOnCall yet, it’s already going out to impacted individuals. This means if you use its telehealth services or even if your doctor uses its after-hours on-call answering service, you could soon be getting a letter in the mail.

Just like with the IRS, data breach notifications are sent out via the mail as opposed to email, so if you think you might be affected, you’re going to want to keep a close eye on your mailbox over the coming days/weeks.

Generally, after a significant breach, businesses provide all impacted customers with free access to the best identity theft services. In this case, though, ConnectOnCall is just providing identity and credit monitoring services through Kroll for the limited number of people whose Social Security numbers were exposed in this security incident.

If that includes you and you do get this letter, I’d recommend signing up for this service immediately. While we haven’t reviewed Kroll yet, it currently has an A- rating with the Better Business Bureau and has been in business for 29 years. Recovering from identity theft on your own can take years as well as be very costly, so this is an offer you’re not going to want to miss.

For those who don’t get this offer, it still might be worth signing up for identity theft protection as all of your other personal and medical info could be used by hackers in their attacks. For instance, you’re going to want to be extra careful when checking your inbox, as hackers often use info like this in targeted phishing attacks. Likewise, you will want to check your bank and other financial statements for irregularities, as they could be signs of fraud.

Medical data breaches seem to be all the rage with hackers now, and for good reason. These companies store all sorts of sensitive data and have the money necessary to pay a ransom to stop hackers from leaking their stolen info.

There’s not much you can do in a data breach like this one since it wasn’t your computer that got hacked. Still, though, by practicing good cyber hygiene and signing up for any services offered to you, you can avoid having your identity stolen after a data breach.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
An open lock depicting a data breach
More than 3.3 million people hit by employee screening data hack — what you need to know
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
Screen graphic showing data breach warning
5 worst data breaches of 2024 — including the mother of all breaches
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)