HOUSTON—Doctor's Choice Home Care & Hospice announced a data security incident that may have affected some patients' personal and health information. While Doctor's Choice (DC) said it is unaware of any confirmed misuse of this information, it published a release providing details of the incident, the company's response and resources available to patients as required by HIPAA regulations.
The company said that between June 5, 2026, and July 24, 2026, an unauthorized party gained access to a single clinical user account within the WellSky electronic medical record (EMR) system via compromised credentials in the WellSky platform. DC said it discovered the incident on July 21 and immediately began investigating with WellSky. The company's chief technology officer has confirmed that this account was the only point of unauthorized access. It also reviewed its own internal systems and found no related unauthorized activity.
"We take this incident very seriously," DC said. "Upon learning of this incident, we immediately disabled the affected account. We confirmed the scope of access with WellSky and completed an internal review that found no other Doctor's Choice Home Care systems involved. We are actively engaged in working with WellSky to ensure they strengthen their security controls to help prevent a recurrence. We have notified the City of Houston Police Department, and they have an active case assigned for investigation. Although we are unaware of actual misuse, as an added precaution, we are offering our patients access to credit monitoring at no cost to them."
DC said it has no evidence at this time that patient information has been misused, but recommend patients remain vigilant.
