Breach Analysis8 min read

CallonDoc, Inc. Data Breach Analysis

Analysis of the CallonDoc, Inc. data breach disclosed 2025-12-22

By MedSecLedger
Records: Unknown
Vector: hacking
Status: confirmed
Occurred: Dec 28, 2025Discovered: Dec 28, 2025Disclosed: Dec 22, 2025
Exposed:protected health information

Breach Summary

Call-on-Doc, Inc., a Dallas-based telehealth provider, has confirmed that an unauthorized party accessed its network and potentially viewed or acquired patients' protected health information (PHI). The company disclosed the incident in notification letters dated September 18, 2026 — nearly nine months after the unauthorized access began. The exact number of affected individuals has not been made public, and the specific categories of exposed data were left blank in the template notification letter reviewed for this analysis, a detail that itself raises questions about the completeness of Call-on-Doc's disclosure to affected patients.

What is clear from the letter: attackers had access to Call-on-Doc's environment for roughly two weeks, and the company took more than seven months to determine what data was compromised and notify those affected. For a telehealth platform — a business model built entirely on collecting sensitive clinical and identity data during virtual visits — that timeline should concern every compliance officer watching the sector.

Timeline of Events

The dates in Call-on-Doc's own letter tell a story of a slow-moving incident response:

  • December 22, 2025 – January 3, 2026: The window during which unauthorized access and potential data acquisition occurred.
  • December 28, 2025: Call-on-Doc says it "became aware of unauthorized access in its network" — meaning the intrusion was detected while still in progress, roughly six days after it began.
  • August 19, 2026: The company determined that PHI had been potentially accessed and/or acquired. This is more than seven and a half months after detection.
  • September 18, 2026: Written notifications sent to affected individuals — roughly one month after the forensic determination, and just under nine months after the original intrusion.

Under the HITECH Act's breach notification requirements, covered entities and business associates must notify affected individuals "without unreasonable delay" and no later than 60 days following discovery of a breach involving 500 or more individuals — discovery being defined as the point the entity knew or should have known a breach occurred, not the point a full forensic review concluded. If Call-on-Doc's incident affects 500 or more individuals, the gap between the December 2025 detection and the September 2026 notification is the kind of delay that HHS Office for Civil Rights (OCR) has scrutinized in prior enforcement actions, particularly where an entity's own investigation timeline stretches into multiple quarters. Investigation complexity is a legitimate factor OCR will consider, but a nine-month span from detection to notice invites the question of whether mitigation and forensic scoping moved with appropriate urgency, or whether the entity is treating the 60-day clock as starting only once its own investigation is "complete" rather than when the breach was first known.

This pattern — early detection, prolonged investigation, delayed notice — echoes what we saw at Cookeville Regional Medical Center, where the gap between compromise and public notification similarly drew out well past what patients would consider reasonable.

What Data Was Exposed

Call-on-Doc's notification letter is unusual in that the section meant to enumerate the specific data types involved — "The information that may have been accessed contained your ___" — appears to have been left as a template placeholder rather than filled in with the actual categories, at least in the version reviewed here. The letter does confirm that protected health information was among the data potentially accessed or acquired, and it includes a dedicated section titled "Protecting Your Medical Information," a template segment HHS-regulated notification letters typically include only when clinical or diagnostic data is confirmed to be part of the exposure.

For a telehealth company, the realistic universe of data types tied to a patient record includes:

  • Full name, date of birth, and contact information
  • Insurance and billing details
  • Visit history, diagnoses, prescriptions, and clinical notes
  • Login credentials for the patient portal
  • In some telehealth models, Social Security numbers collected for billing or identity verification

PHI carries risks that go beyond the identity-theft calculus of a typical consumer data breach. Medical identity theft can result in fraudulent billing, corrupted medical records that follow a patient across providers, and denial of insurance claims — harms that are often more difficult to unwind than a fraudulent credit card charge. Combined with prescription and diagnosis data, exposed PHI can also be used for targeted phishing and extortion schemes that reference a patient's actual health conditions, which is precisely why the notification letter's credit-monitoring boilerplate (fraud alerts, security freezes, annual credit reports) addresses only part of the real risk surface here.

How the Attack Happened

Call-on-Doc's letter offers minimal technical detail, describing only "unauthorized access in its network," classified here under the broader "hacking" attack vector. The company states it took "certain systems offline" upon detection and engaged external incident response professionals — standard containment steps, but the letter does not disclose an initial access vector (phishing, credential compromise, exploited vulnerability, or third-party access), nor does it indicate whether ransomware or data exfiltration tooling was involved. The absence of that detail is common in early notification letters but leaves peer organizations unable to draw specific defensive lessons, beyond the general observation that a telehealth platform's internet-facing patient portal and API infrastructure represent an expanded attack surface relative to a traditional single-location provider.

Regulatory Implications

Call-on-Doc almost certainly qualifies as a HIPAA covered entity given its role delivering telehealth services directly to patients, placing it squarely under the HIPAA Privacy Rule and Security Rule (45 CFR Parts 160 and 164). Several compliance threads are worth watching as this incident develops:

  • Security Rule risk analysis: OCR investigations of breaches involving network intrusions routinely focus on whether the covered entity had conducted an accurate and thorough risk analysis under 45 CFR 164.308(a)(1), and whether access controls, audit logging, and encryption of ePHI at rest and in transit met the standard expected for a platform handling clinical data at scale.
  • Breach notification timeliness: As noted above, the roughly nine-month gap between the start of unauthorized access and patient notification will be a focal point if OCR opens an investigation, particularly the seven-plus months between detection and the determination that PHI was involved.
  • Business associate exposure: If Call-on-Doc uses third-party vendors for scheduling, payment processing, EHR hosting, or pharmacy integration, any of those relationships governed by a business associate agreement (BAA) could face parallel scrutiny depending on where in the technical environment the unauthorized access occurred.
  • State health privacy law overlap: Beyond HIPAA, telehealth companies increasingly fall within the scope of state consumer health data laws such as Washington's My Health My Data Act and Connecticut's health data privacy amendments, both of which apply broader definitions of "consumer health data" than HIPAA's PHI definition and carry their own notification and consent obligations — potentially independent of HIPAA's covered-entity framework.
  • State AG notification: Given Call-on-Doc's national telehealth footprint, multiple state attorneys general will likely receive notice under their respective breach notification statutes, several of which impose shorter notification windows than HITECH's 60-day standard.

The Bigger Picture

Telehealth's rapid expansion since 2020 has outpaced the security maturity of many platforms in the space, and breaches at digital-first providers like CareCloud and Clinical Registry Solutions reflect a broader pattern: healthcare organizations that built patient-facing digital infrastructure quickly are now facing the security debt that comes with it. HHS OCR's enforcement priorities and the HHS Health Sector Cybersecurity Coordination Center (HC3) have both flagged network intrusions and delayed detection as persistent weaknesses across the sector, and the American Hospital Association has repeatedly warned that ransomware and unauthorized-access incidents at third-party technology vendors now represent a bigger share of total patient records exposed annually than incidents at hospitals themselves.

CISA's Healthcare and Public Health Cybersecurity Performance Goals (CPGs) specifically call out asset inventory, network segmentation, and centralized log collection as baseline controls — the kind of foundational visibility that would typically shorten the gap between "unauthorized access begins" and "we know what was taken." A near-eight-month investigation window suggests either a genuinely complex environment to forensically reconstruct, or gaps in logging and monitoring that made scoping the incident far harder than it should have been.

Action Items for Peer Organizations

  1. Audit detection-to-scoping timelines. If your organization's incident response plan doesn't have a defined target for moving from "we detected something" to "we know what data was involved," build one now — and stress-test it against a tabletop exercise involving a network-wide intrusion.
  2. Verify logging coverage across patient-facing systems. Telehealth and portal infrastructure often sits partially outside traditional EHR logging; confirm that authentication, data access, and export events are captured and retained long enough to support a forensic investigation without months of reconstruction.
  3. Review BAAs and vendor security requirements. Any third party touching ePHI — scheduling, billing, e-prescribing, video infrastructure — should be subject to periodic security assessments, not just a signed BAA on file.
  4. Map state health privacy law exposure separately from HIPAA. Laws like Washington's My Health My Data Act apply to a broader set of "consumer health data" and may trigger obligations even when HIPAA's covered-entity analysis is ambiguous.
  5. Pressure-test your breach notification workflow against the 60-day clock. Legal, compliance, and IR teams should agree in advance on what "discovery" means under HITECH, so notification timelines aren't inadvertently extended by treating the completion of a full forensic report as the trigger date.
Tags:breachotherprotected health informationhacking