DataBreachSearch.com
All cases
monitoring

Ocracoke Health Center Confirms Data Breach in Vermont

Ocracoke Health Center, Inc. reported a data security incident to Vermont authorities on September 16, 2026. The breach exposed sensitive patient information, including medical and identification details, creating potential risks for affected individuals.

Compiled from official Attorney General recordsLast updated
State
Vermont
Reported
September 16, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

Ocracoke Health Center, Inc. filed an official report with Vermont state authorities on September 16, 2026, acknowledging a data security incident. The incident’s exact nature is unspecified, and the investigation status is currently listed as monitoring.

According to the public filing, the breach led to the exposure of several categories of highly sensitive personal data. These include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates.

Such an extensive compromise of personal and health-related information can pose significant risks to those affected. The exposure of identifying details like Social Security Numbers and Full Names could increase the risk of identity theft. Additionally, the compromise of specific medical data may open individuals to medical fraud or other privacy violations.

Individuals who receive a breach notification from Ocracoke Health Center, Inc. should consider taking protective measures. It is advisable to carefully review Explanation of Benefits statements from health insurers and monitor financial accounts for any suspicious activity. Placing a fraud alert or security freeze on your credit reports with major credit bureaus is also a widely recommended step. Exercise caution regarding any unsolicited communications, as exposed data can be used in targeted phishing or scam attempts.

Source: Attorney General filing