
Houston, Texas-based Blue Fish Pediatrics has revealed that a data security incident it suffered last year compromised the sensitive personal information of more than 60,000 individuals.
Blue Fish Pediatrics is a Texas-based healthcare provider that delivers comprehensive medical care for infants, children, and adolescents through a network of clinics. Its services include preventive care, regular health checkups, vaccinations, and treatment for a range of childhood illnesses.
Blue Fish Pediatrics said in a data security incident notice published on its website that it discovered a security incident affecting its internal network on July 17. The healthcare provider said it promptly initiated an investigation, engaging external cybersecurity experts to assess the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“After an extensive forensic investigation and manual document review, we discovered on May 4, 2026, that between July 11, 2025 and July 17, 2025, a limited number of files potentially accessed or acquired by the unauthorised party,” Blue Fish Pediatrics said.
The compromised data includes names, Social Security numbers, dates of birth, driver’s license and state identification numbers, medical record numbers, diagnosis/conditions information, lab results, medications information, healthcare claims information, and clinical/treatment information.
Blue Fish Pediatrics initially reported to the Texas Attorney General’s Office that at least 41,485 individuals were affected by the incident. However, a subsequent filing with the U.S. Department of Health and Human Services’ Office for Civil Rights increased the estimated number of affected individuals to 62,150.
While the healthcare provider said it found no evidence that the compromised information had been misused, it urged affected individuals to closely monitor their credit reports, account and benefit statements for any suspicious activity and to report potential identity theft or fraud to law enforcement, including local police and the state attorney general.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Blue Fish Pediatrics. The healthcare provider also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543