
Terry J. Dubrow, MD, A Medical Corporation, the practice associated with plastic surgeon and television personality Dr. Terry Dubrow, recently notified patients of a data security incident that may have exposed sensitive personal and medical information. If you received a Dubrow data breach notification letter, it is worth understanding what happened, what information may have been involved, and what legal options may be available to you. Contact our data breach attorneys to learn more.
According to a notification submitted to the California Attorney General's office, the Practice was contacted by an unauthorized actor who claimed to have accessed portions of its digital systems. Following that contact, the Practice engaged forensic investigators and reported the matter to the FBI. The investigation reportedly determined that an unauthorized party accessed a portion of the Practice's network beginning on January 16, 2025, and acquired certain files during that time. It was not until July 27, 2026, that the Practice identified which individuals had personal information contained in the affected files, and breach notification letters began going out in mid-August 2026.
The Practice states it has no evidence at this time that the acquired information has been misused or publicly shared, and that it believes the incident has been contained. Patients should know that these assessments can evolve as investigations continue, and vigilance remains important regardless of a company's current findings.
Based on the notification letter, the information involved in the Dubrow patient data breach may include:
The inclusion of Social Security numbers alongside detailed medical and cosmetic procedure records is notable, since this combination can create heightened risk for identity theft, medical identity fraud, and privacy harm that goes beyond typical financial data exposure.
When a medical practice collects and stores Social Security numbers, treatment records, and identifying documents, it has a legal duty to maintain reasonable safeguards to protect that data. When a breach occurs, affected patients may have legal grounds to pursue a data breach lawsuit or join a class action seeking compensation for the time, expense, and risk created by the exposure of their information. It is important to note that a data breach notification alone does not establish fault, and any conclusions about the cause of an incident should be based on a full legal and factual review by a qualified data breach lawyer.
If you received a data breach notification from Terry J. Dubrow, MD, A Medical Corporation, The Lyon Firm can help you understand your rights and evaluate whether you may be entitled to compensation. Our firm has extensive experience representing individuals affected by healthcare data breaches involving Social Security numbers and medical records. We offer free, confidential consultations and work to hold organizations accountable when patient data protection falls short. Contact The Lyon Firm today to discuss your potential Dubrow data breach case.
This is an initial investigation based on public reporting. Nothing in this article should be construed as an accusation of wrongdoing or a determination of legal liability on the part of Terry J. Dubrow, MD, A Medical Corporation, or any related individual or entity.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: