Phreesia Reports Unauthorized System Access Incident to Texas AG
Phreesia, Inc. has formally reported a data security incident to the Texas Attorney General, confirming unauthorized access to its systems on August 17, 2025. This event potentially exposed personal information managed by the healthcare technology provider. An investigation into the full scope of the breach is currently underway.
- State
- Texas
- Breach date
- August 17, 2025
- Reported
- February 6, 2026
Phreesia, Inc., a healthcare technology company, officially reported a data security incident involving unauthorized access to its systems. This event was reported to the Texas Attorney General on February 6, 2026, stemming from an incident that occurred on August 17, 2025. The company specializes in providing patient intake and management software for medical practices and health systems.
Due to the nature of Phreesia's services, the company handles significant volumes of personal information to facilitate patient registration and billing processes. The public filing indicates that unauthorized access occurred, meaning that individuals' personal data stored within Phreesia's environment may have been compromised. Specific categories of information exposed have not been detailed in the public record.
Individuals who receive a formal data breach notification letter from Phreesia should understand that their personal information was potentially impacted by this security event. Phreesia has stated that it is currently investigating the scope of this breach to understand the full extent of the exposure. This process aims to clarify how the incident may affect individuals whose data was involved.
If you have been notified of this incident, it is prudent to remain vigilant for any unusual activity. Consider reviewing statements from healthcare providers or other relevant accounts for discrepancies. It is also recommended to be cautious of unsolicited communications, as phishing attempts often follow data security incidents.
Regularly monitor any accounts linked to services where you may have provided information to Phreesia. If available, consider enabling multi-factor authentication on all online services to add an extra layer of security. Staying informed about any updates from Phreesia or regulatory bodies regarding this incident is also advisable.