Almeida Law Group is investigating a data breach at Visiting Nurse Association of Texas. The breach occurred on January 27th, 2025 – July 18th, 2025 and was discovered on July 17th, 2025. If you were affected, contact Almeida Law Group.
About Visiting Nurse Association of Texas
Visiting Nurse Association of Texas (VNA) is a nonprofit 501(c)(3) organization founded in 1934 and headquartered in Dallas, Texas. It provides in-home healthcare services to older adults across North Texas, including hospice care, palliative care, caregiver support, and Meals on Wheels nutrition services for homebound seniors and disabled adults. VNA operates five branch locations across the region. Because VNA provides direct medical and social services to patients, it collects sensitive personal, medical, and financial information as part of its work.
What Happened?
Visiting Nurse Association of Texas was listed in a Texas Attorney General data security breach report (record ID BR-0005191) published on July 21st, 2026. According to VNA’s own privacy incident notice, on July 17th, 2025, VNA detected unusual activity on its network and launched an investigation with the help of third-party computer forensics experts. The investigation determined that an unauthorized individual had accessed certain employee email accounts. VNA secured its environment, implemented additional technical safeguards, and conducted a comprehensive review of the affected accounts to identify impacted individuals and data types. The compromised information included names, Social Security numbers, driver’s license numbers, medical information, health insurance information, and dates of birth. A total of 28,467 individuals were affected. VNA notified consumers by U.S. Mail, print media publication, and a posting on its website, and is offering complimentary credit monitoring services to those affected. Consumer notification began around October 2025, with an updated notice posted on January 30th, 2026.
The TX AG filing reflects a breach window running from January 27th, 2025 through July 18th, 2025—nearly six months of unauthorized access before discovery. No ransomware group claim or threat-actor attribution has been reported. No class action lawsuit has been filed, but at least two law firms—Strauss Borrelli PLLC and Shamis & Gentile P.A.—have publicly announced investigations into the breach on behalf of potentially affected individuals.
Key Facts at a Glance
- Company or Organization: Visiting Nurse Association of Texas
- Industry: Healthcare – Nonprofit Home Health / Hospice / Palliative Care / Meals on Wheels
- Location: Dallas, Texas
- Incident type: Unauthorized access to employee email accounts
- Date of breach: January 27th, 2025 – July 18th, 2025
- Date breach discovered: July 17th, 2025
- Date of consumer notification: On or around October 10th, 2025 (updated January 30th, 2026)
- Total persons affected: 28,467
- Identity theft protection offered: Yes – complimentary credit monitoring
- Prior breach: None identified
- Litigation status: No lawsuit filed; investigations announced by Strauss Borrelli PLLC and Shamis & Gentile P.A.
- Source: Texas Attorney General data security breach report (BR-0005191), https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0005191; VNA Texas Notice of Privacy Incident, https://www.vnatexas.org/notice-of-privacy-incident-october-10-2025/; Strauss Borrelli PLLC investigation, https://straussborrelli.com/2026/01/30/visiting-nurse-association-of-texas-data-breach-investigation/
What Should You Do?
If you received a notice from Visiting Nurse Association of Texas, enroll in the complimentary credit monitoring VNA is offering before any stated deadline. Because the breach included Social Security numbers, driver’s license numbers, medical information, and health insurance information, you should also consider placing a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion. Review your credit reports for unfamiliar accounts or inquiries at AnnualCreditReport.com, where you can request free reports. Because health and insurance information was involved, carefully review any Explanation of Benefits statements from your health insurer and check your medical records for services or claims you do not recognize. If you spot signs of identity theft or fraud, report them at IdentityTheft.gov for step-by-step recovery guidance.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.