Almeida Law Group is investigating a data breach at Capitol Pain Institute. The breach occurred on September 5th–6th, 2026 and was discovered on September 7th, 2026. If you were affected, contact Almeida Law Group.
About Capitol Pain Institute
Capitol Pain Institute (CPI) is a multi-state medical practice focused on pain management and treatment for chronic pain conditions. Founded in 2007 by Dr. S. Matthew Schocket, the practice is headquartered in Austin, Texas and operates clinics across Texas, Colorado, Indiana, Kentucky, and Ohio. It provides services including interventional pain management, spinal cord stimulation, medication management, physical therapy, and behavioral health support. The company is privately held and private equity-backed, with between 201 and 500 employees.
What Happened?
Capitol Pain Institute was listed in a Texas Attorney General data security breach report (record BR-0005400), published on October 6th, 2026. The breach occurred on September 5th and 6th, 2026 and was discovered on September 7th, 2026. According to the filing, the types of information involved include names, addresses, dates of birth, and one additional unspecified category described only as “Other” in the report. No further details about that category were available in the source materials. A total of 666 individuals were affected. The Texas AG filing indicates that consumer notice has not yet been provided to those affected.
This appears to be a second, separate breach from an earlier incident that Capitol Pain Institute reported to the U.S. Department of Health and Human Services on May 1st, 2026, which affected 695 people. That earlier breach was the subject of a lawsuit investigation by Shamis & Gentile P.A. No confirmed litigation related to the current September 2026 incident has been found, and no ransomware group or specific threat actor has been publicly linked to it.
Key Facts at a Glance
- Company or Organization: Capitol Pain Institute
- Industry: Healthcare – Medical Provider (Pain Management / Clinics/Outpatient Services)
- Location: Austin, Texas
- Incident type: Unauthorized access/data breach
- Date of breach: September 5th, 2026 – September 6th, 2026
- Date breach discovered: September 7th, 2026
- Date of consumer notification: Not yet provided as of the filing date
- Total persons affected: 666
- Prior breach: Yes – a separate breach reported to HHS on May 1st, 2026 affected 695 people
- Litigation status: Shamis & Gentile P.A. was investigating the earlier May 2026 breach; no confirmed litigation related to the September 2026 incident
- Source: Texas Attorney General Data Security Breach Report (BR-0005400); ClaimDepot – Capitol Pain Institute Data Breach Lawsuit Investigation; Capitol Pain Institute LinkedIn Profile
What Should You Do?
If you believe your information was involved in this breach, consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to help prevent unauthorized accounts from being opened in your name. Monitor your financial accounts and regularly review your credit reports, which you can access for free at AnnualCreditReport.com. If you become a victim of identity theft or suspect fraudulent activity, visit IdentityTheft.gov for step-by-step guidance. Because Capitol Pain Institute is a medical provider, also review any Explanation of Benefits statements from your insurer and request a copy of your medical records to check for errors or unfamiliar entries that could indicate misuse of your health information.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.