Integrated Pain Associates (IPA) identified suspicious system activity in February 2026, which led to a data breach. The company confirmed unauthorized access to its systems and disclosed the incident publicly on April 30, 2026, with the assistance of third-party specialists. IPA stated that it notified law enforcement and is reviewing its data protection policies.
The breach may have exposed individuals' first and last names, along with various combinations of addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnosis/condition information, medication details, health insurance information, provider names, other treatment specifics, and financial account information. The number of affected individuals has not been publicly disclosed, although the company stated it would notify those impacted directly. The breach primarily affected individuals in Central and West Texas. The company is offering free credit monitoring and identity protection to affected individuals.
Details can emerge later as investigations continue, and notices to affected individuals may be delayed.