Three Oaks Hospice data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Three Oaks Hospice, a Dallas-based hospice provider, said it discovered unauthorized activity in its email environment on August 8, 2025, then investigated, contained and remediated it. In a notice published September 17, 2026, the company said that on July 20, 2026, after what it called an extensive investigation, it determined the activity had affected personal information. It notified its affected affiliated hospices on August 17, 2026.
That is a gap of more than eleven months between discovering the intrusion and determining whose information was involved, and the company states both dates itself.
Three Oaks has not published a company-wide total. Three filings with the Texas Attorney General, all published September 17, 2026, give counts per affiliate: Three Oaks Hospice of Dallas, 6,032 people; Three Oaks Hospice of Austin, 427; and Elevation Hospice of Utah, 2,003. Those add to 8,462 across the three filings, which is arithmetic rather than a figure anyone has published, and other sister brands have no Texas filing, so the real number is probably higher. The Texas filings put the intrusion window at July 16 to August 8, 2025.
Sister brands named on the notice include Agape Hospice Care, Elevation Hospice of Colorado, Elevation Hospice of Utah and Sage Hospice, with locations across several states. The company says it is unaware of any actual or attempted misuse of the information. The notice describes a call center and support resources; it does not offer credit monitoring.
Sources
What data was exposed
The following types of personal data were compromised. Three Oaks said not every element was present for every person.
- Names
- Dates of birth
- Driver's license numbers
- Social Security numbers
- Medical information
- Health insurance information
The three Texas filings list names, Social Security numbers, dates of birth, medical and health insurance information, and do not list driver's licence numbers, which appear only on the company's own notice.
Breach details
| Detail | Value |
|---|---|
| Breach name | Three Oaks Hospice |
| Date | July 16 to August 8, 2025 (per Texas filings) |
| Disclosed | September 17, 2026 |
| Accounts affected | 6,032 (Dallas), 427 (Austin), 2,003 (Elevation Hospice of Utah); no company-wide total published |
| Domain | threeoakshospice.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Three Oaks Hospice or its affiliates; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- If your letter names a Social Security number or driver's licence number, place a free credit freeze with Equifax, Experian and TransUnion.
- Review Explanation of Benefits statements and provider bills for care you did not receive. Hospice and related billing is a common target for medical identity theft.
- Treat calls, texts or emails that mention hospice care, insurance details or a request to "verify your records" as possible phishing. Use the number on your mailed notice or the company's website.
- Keep the letter. Three Oaks lists a call centre at 1-800-610-8565, Monday to Friday, 7am to 7pm Central, excluding major US holidays.
- The company is not offering credit monitoring, so anything you set up is your own. A freeze is free and is the stronger control.
- If a family member was the patient, the notice may reach their estate rather than you. Ask the call centre how to confirm.
I got a Three Oaks notice. Does that mean my medical file is on the open web?
No. The company described unauthorised activity in its email environment that was later found to include personal information for some people, which is not a public people-search listing. Rely on your mailed notice and the call centre it names to know whether you were affected. If the letter names an SSN or driver's licence, freeze your credit.
Frequently asked questions
Can Delist remove my data from Three Oaks' email systems or a dump?
No. Delist does not access hospice email archives or remove dump copies. Open-web removal, meaning people-search and similar listings, is a separate pipeline.
Why do the Texas filings show different counts?
Each filing covers one affiliate, such as Dallas, Austin or Elevation Hospice of Utah. No company-wide total has been published, and other sister brands may have no Texas filing, so adding the numbers up does not give you an official total.
What should I do after the letter?
Verify it through the notice or call centre, freeze your credit if an SSN or driver's licence is named, review Explanation of Benefits statements for care you did not receive, and keep the letter. Three Oaks is not offering credit monitoring, so a freeze is the stronger control.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- Aesto Health breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.