CallonDoc, Inc. Data Breach Notice (California Attorney General): What Was Exposed & What To Do
CallonDoc, Inc. disclosed a data breach on September 17, 2026, after personal information was exposed in an incident that occurred on December 22, 2025. Individuals who provided information to the organization should review the notice posted by the California Attorney General and take recommended protective steps.
Healthcare and telemedicine providers remain frequent targets in a threat landscape where stolen personal information can be reused for fraud, identity misuse, and follow-on social engineering. Against that backdrop, CallonDoc, Inc. has notified California residents of a data breach, according to a filing reported to the California Attorney General on September 17, 2026. The same filing places the underlying incident on December 22, 2025. Public detail is limited: the number of people affected is unknown, and the notice describes exposed material in broad terms as personal information.
For patients and others who may have interacted with the company, the gap between the incident date and the public report, together with the lack of a published headcount, makes clear what is confirmed and what is not. The remainder of this article stays within those bounds and explains why even a high-level notice of this kind still matters.
Breaking down the breach
According to the California Attorney General filing dated September 17, 2026, CallonDoc, Inc. notified California residents that a data breach had occurred. The filing identifies the incident date as December 22, 2025. Beyond that timeline, the public record provided here does not describe how the incident was discovered, whether systems were encrypted or exfiltrated, how long unauthorized access lasted, or whether a third party or insider was involved.
The number of people affected is listed as unknown. The notice characterizes the exposed material as personal information, without a further public inventory of fields in the materials supplied for this account. No dollar figures, file names, or technical indicators appear in the facts available here. Attribution to any named threat group is also absent; nothing in the disclosure identifies a specific actor.
In short, the confirmed picture is narrow: a company operating in the health-adjacent services space reported a December 22, 2025 incident to California authorities in a September 17, 2026 filing, and described the data involved as personal information. Everything else about method, scale, and precise data elements remains undisclosed in the record used for this article.
How a breach like this happens
Incidents described only as involving “personal information” at a consumer-facing health or telehealth-style organization typically follow a small set of well-understood patterns. None of the following is stated as the cause of the CallonDoc event; these are general background patterns seen across the sector.
Attackers often gain an initial foothold through stolen or guessed credentials, phishing that yields remote-access logins, exposed remote services, or unpatched software on internet-facing systems. Once inside, they may move laterally to systems that store patient or customer records, billing data, or identity documents. In other cases, a misconfigured cloud storage bucket, an unsecured backup, or a compromised business partner with network or API access can expose the same classes of data without a dramatic “break-in.”
Detection can lag for weeks or months if logging is incomplete or if the activity blends with normal administrative traffic. Notification timelines then depend on forensic scoping, legal review, and statutory deadlines such as those that apply when California residents’ information is involved. Because no method is attributed in the CallonDoc filing facts, it is not possible to say which of these paths—if any—applied here. The patterns above simply explain how organizations of this type commonly experience unauthorized access or disclosure of personal information.
About CallonDoc, Inc.
CallonDoc, Inc. operates in the online and telehealth-adjacent medical services space, connecting consumers with clinicians for remote consultations, prescriptions, and related care pathways. Organizations in this sector routinely collect and process information needed to identify patients, deliver care, bill for services, and meet regulatory and pharmacy requirements.
That operational model means such companies typically hold identity data, contact details, and health-related information tied to visits or prescriptions. A breach notice from a firm in this position is consequential because the same records that enable convenient remote care are also useful to criminals who commit medical identity fraud, open fraudulent accounts, or craft convincing scams that reference real appointments or conditions. The California Attorney General filing establishes that CallonDoc treated the December 2025 incident as one requiring notice to California residents; it does not, by itself, establish negligence or the full scope of systems involved.
What data was at risk
The breach notification, as reflected in the facts, names the exposed material as personal information. It does not publish a field-by-field list in the summary available here. Exact contents are therefore unconfirmed beyond that label.
Organizations that provide telehealth or direct-to-consumer medical services commonly maintain names, addresses, phone numbers, email addresses, dates of birth, and government or insurance identifiers, along with clinical or prescription-related details necessary for care. Payment card or banking fragments may also appear in billing systems. None of those categories should be read as a confirmed inventory for this incident. Only “personal information” is stated in the notice facts; readers should treat any more specific list as typical for the sector, not as proven for CallonDoc’s December 22, 2025 event.
Why it matters
When personal information from a health-related service is exposed, affected people face concrete risks that extend beyond a single password reset. Identity thieves can combine name, date of birth, and contact data with other leaked sets to impersonate someone to insurers, pharmacies, or creditors. Fraudulent medical claims can distort records and create billing disputes. Targeted phishing that references a real provider name is often more convincing than generic spam.
For the organization, a reportable breach brings notification costs, potential regulatory scrutiny under state breach laws, and reputational pressure from patients who expect clinical and administrative data to remain confidential. Because the number of affected individuals is unknown in the public facts, the aggregate impact cannot be quantified here. The delay between the stated incident date (December 22, 2025) and the September 17, 2026 California filing also means some people may only now be learning that their information could have been involved, which can complicate timely monitoring.
None of this requires assuming worst-case technical details that were never published. Even a high-level confirmation that personal information was involved is enough to justify careful personal monitoring and a clear-eyed view of residual fraud risk.
If your data was in this breach
If you are a California resident who used CallonDoc or received a notice tied to this filing, treat the company’s communication as the primary source for what applies to you. Preserve the notice. Consider placing a fraud alert or credit freeze with the major consumer credit reporting agencies if identity elements may have been involved. Monitor bank, credit card, and insurance statements for unfamiliar activity, and be skeptical of unsolicited calls or messages that reference your care or this incident and press for payments or passwords.
Change passwords on related accounts if you reused them elsewhere, and enable multi-factor authentication where available. If you believe clinical or insurance records were affected, contact your insurer or clinician’s office through official channels to ask how to flag your file. For a broader check on whether your email address has appeared in other known breach corpora, you can run a free exposure scan of your email through reputable breach-notification lookup services and then prioritize remediation on any confirmed hits.
Public detail on this specific event remains limited to the California Attorney General filing timeline and the description of personal information. Staying within those facts—and taking ordinary identity-protection steps—is the most reliable response until CallonDoc or regulators publish additional confirmed information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Opportune LLP Data Breach Notice (California Attorney General)Partnership HealthPlan of California Data Breach Notice (California Attorney General)Tarter Krinsky & Drogin LLP Data Breach Notice (California Attorney General)Leggett & Platt, Incorporated Employee Benefits Plan Data Breach Notice (California Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.