Call-On-Doc Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Call-On-Doc
Active investigation Data breach · Healthcare Notices mailed Sep 18, 2026

Received a September 2026 breach notice from Call-On-Doc?

Dapeer Law, P.A. is investigating a potential class action against Call-On-Doc, Inc. (also known as CallonDoc), a Dallas, Texas telehealth provider, on behalf of patients whose protected health information may have been exposed in the December 2025 network intrusion.

Submit your claim → See what to do No fee unless we recover for you
Breach window
Dec 22, 2025 to Jan 3, 2026
Unauthorized network access
Notification delay
About 9 months
Discovered Dec 2025, notices Sep 2026
Credit monitoring
Not offered
No complimentary monitoring in the notice
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Call-On-Doc dated September 2026.
  • Your letter states that your protected health information may have been accessed in the incident.
  • You were a patient of Call-On-Doc and had personal or health information held by the company in its capacity as an online healthcare provider.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

Call-On-Doc, Inc. ("Call-On-Doc"), a Dallas, Texas telehealth provider that offers online medical consultations and prescriptions, states that it became aware of unauthorized access in its network on December 28, 2025. The company reports that it took affected systems offline and engaged outside cybersecurity professionals to investigate. The forensic review determined that an unauthorized party had access to certain systems between December 22, 2025 and January 3, 2026.

According to the notice, Call-On-Doc determined on August 19, 2026 that protected health information belonging to certain patients may have been accessed. The company reported the incident to the California Attorney General on September 17, 2026 and mailed notice letters to affected patients on September 18, 2026. The public copy of the notice does not itemize the specific data elements involved, and it does not appear to include a complimentary credit monitoring offer. Nearly nine months passed between discovery of the incident and notification of affected patients, a delay that Dapeer Law is evaluating.

Because Call-On-Doc is a healthcare provider, patient information held by the company may be subject to protections under federal and state health-privacy laws. Exposure of health information can raise the risk of medical identity theft and insurance fraud in addition to financial fraud. The exact categories of data involved for any individual are described in that person's own notice letter.

Telehealth Protected Health Information Network Intrusion California Attorney General Notification Delay
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Call-On-Doc notice. The letter documents that your information may have been involved and is important evidence if you decide to participate in a lawsuit.

2

Freeze your credit and monitor your accounts

Because the notice does not appear to include a complimentary credit monitoring offer, place a free security freeze and fraud alert with Equifax, Experian, and TransUnion, request your free credit reports, and review your account statements for charges you do not recognize. Taking these steps does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because health information may have been involved, also review your insurance explanation-of-benefits statements and pharmacy and medical billing records for services or prescriptions you did not receive.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

Dec 22, 2025 Passed
Unauthorized access to Call-On-Doc systems begins
Dec 28, 2025 Passed
Unauthorized access discovered, systems taken offline
Jan 3, 2026 Passed
Unauthorized access period ends
Aug 19, 2026 Passed
Review confirms protected health information may have been accessed
Sep 17, 2026 Passed
Notice filed with the California Attorney General
Sep 18, 2026 Passed
Letters mailed to affected patients
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, medical-claim fraud, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring the company to implement stronger data security practices to protect patient information going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Call-On-Doc. What should I do? +

Keep your notice letter, place a fraud alert or security freeze with Equifax, Experian, and TransUnion, request your free credit reports, and monitor your account statements for unfamiliar charges. Because the breach involves a telehealth provider, also watch your insurance explanation-of-benefits statements and pharmacy records for services or prescriptions you did not receive. You may also speak with a data breach attorney about your options.

Am I eligible to join a class action against Call-On-Doc? +

Patients who received a notice letter from Call-On-Doc are the most likely to qualify. Eligibility can also depend on your state of residence, the categories of your information that were involved, and whether you have experienced any losses or fraud. An attorney can review your individual notice and advise you.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

Call-On-Doc states that protected health information belonging to certain patients may have been accessed. The public copy of the notice filed with the California Attorney General does not itemize the specific data elements. Because Call-On-Doc provides online consultations and prescriptions, patient records may include contact details, medical information, and insurance or payment details, but this has not been confirmed. The information affected for you is described in your individual notice letter.

Did Call-On-Doc offer free credit monitoring? +

The notice filed with the California Attorney General does not identify a complimentary credit monitoring or identity protection offer. Instead, the company recommends placing a fraud alert or security freeze and reviewing your free credit reports and account statements. If your letter includes an enrollment code, use it before the stated deadline, since accepting a monitoring benefit does not waive your right to pursue legal action. This page will be updated if an offer is confirmed.

How many people were affected by the Call-On-Doc breach? +

Call-On-Doc has not publicly disclosed the number of affected individuals in its California Attorney General filing. Patients in multiple states may have received letters. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Call-On-Doc filed a copy of its notice with the California Attorney General, whose office makes such filings available to the public on its data breach notification page. Dapeer Law can also help you obtain a copy during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Call-On-Doc, Inc., Not offered, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 18, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

City of Idaho Falls Data Breach Lawsuit Investigation

Next
Next

Alliance Environmental Group Data Breach Lawsuit Investigation