According to a notice published by Blue Fish Pediatrics, the practice began notifying affected individuals Wednesday after determining that an unauthorized party accessed its computer systems during a cyber incident that occurred between July 11 and July 17, 2025.
The company finalized its investigation on May 4, 2026, determining that files belonging to approximately 41,485 Texas residents may have been accessed during the breach and contained personal information belonging to patients and others associated with the practice.
The medical practice has several locations in the Greater Houston area including Cypress, Katy, Missouri City, Shenandoah and Sugar Land.
The information potentially exposed varies by individual but may include:
Blue Fish Pediatrics said it immediately contained the incident after discovering the unauthorized activity and hired cybersecurity experts to investigate what information may have been involved. The company said it has no evidence that identity theft or financial fraud has occurred as a result of the breach.
“Notified individuals have been provided with best practices to protect their information, and individuals whose Social Security numbers were contained in the impacted files have been offered complimentary credit monitoring,” the company said in its notice.
The practice has also established a dedicated response line for patients and families seeking additional information.
“Blue Fish Pediatrics is committed to maintaining the privacy of personal information in its
possession and has taken many precautions to safeguard it,” the notice added. “Blue Fish Pediatrics continually evaluates and modifies its practices to enhance the security and privacy of the personal information it maintains.”
Those who believe they may have been affected can contact Blue Fish Pediatrics at 1-877-311-3743 or review the company’s breach notification materials for additional guidance on protecting their information.