Blue Teal Holdings, LLC, a commercial holding company, experienced a data breach that began on October 13, 2025, and was discovered on May 11, 2026. The company sent written notifications to affected consumers on May 28, 2026, and reported the incident to attorney generals in California, Texas, and Maine.
The breach exposed Protected Health Information (PHI) and Personally Identifiable Information (PII) for approximately 9,748 individuals. This includes names, Social Security numbers, dates of birth or death, driver's license IDs, financial account numbers, credit card numbers, medical diagnoses, health plan names, biometric data, and provider names. The breach affected residents in multiple states, including Texas, Indiana, Massachusetts, Vermont, New Hampshire, Maine, and Rhode Island.
Details about this breach may continue to emerge as investigations proceed. Notices to affected individuals may be delayed.