Texas Psychiatry Practice Discloses Data Breach Affecting Patient Records
Psychiatry of Texas PLLC has notified patients that unauthorized parties gained access to its computer network earlier this year, exposing protected health information belonging to current and former patients as well as individuals treated by healthcare providers the company supports.
The Houston-based practice said it first detected unusual activity on its network on March 31, 2026, and immediately began investigating with the help of outside cybersecurity specialists. That investigation confirmed that an unauthorized actor had accessed company systems and acquired data on that same date, according to a notice filed with regulators and sent to affected individuals.
The compromised information varied by person but may have included full names, Social Security numbers, dates of birth, medical diagnosis and treatment records, health insurance details, electronic identification or account numbers, usernames, email addresses, passwords, and in some cases a parent’s premarital surname. Written notification letters were mailed to affected individuals with known addresses on August 27, 2026, the same date the company issued its public disclosure.
As a precaution, Psychiatry of Texas is offering complimentary credit monitoring and identity protection services through HaystackID to those whose Social Security numbers were involved. The company has also set up a dedicated assistance line, staffed Monday through Friday, for patients seeking to confirm whether their information was part of the breach.
The incident adds to a long list of data security failures reported across the U.S. healthcare sector in recent years. Medical practices and their vendors have become frequent targets for cybercriminals because patient files often contain a dense mix of financial, medical and identity data that can be resold or used for fraud. Behavioral health providers in particular hold especially sensitive records, since diagnosis and treatment histories carry privacy risks beyond typical financial exposure.
Federal law generally requires healthcare organizations to notify affected patients and regulators once a breach involving protected health information is confirmed, and many states impose additional disclosure obligations. Security researchers have repeatedly noted that smaller medical practices and regional providers often operate with more limited cybersecurity budgets than large hospital systems, making them attractive targets for ransomware groups and data thieves seeking sensitive records with fewer defensive obstacles.
Psychiatry of Texas is urging affected patients to monitor account statements and credit reports for signs of misuse and to contact financial institutions promptly if suspicious activity appears. The company also pointed individuals toward resources from the Federal Trade Commission, including guidance on fraud alerts, credit freezes and identity theft complaints.
The notice was reported by PR Newswire, which published the company’s full disclosure of the incident.