VillageCareMAX Data Breach Investigation

Graphic announcing the VillageCareMAX data breach investigation, featuring the Migliaccio & Rathod LLP logo and a background image of preparing weekly pills.

Migliaccio & Rathod LLP is investigating the VillageCareMAX Data Breach, impacting an undetermined number of individuals and their personal information.

What Happened?

VillageCareMAX engaged TMG Health, Inc to provide call center services. TMG Health, Inc discovered that an unauthorized actor had accessed the VillageCare system from November 20, 2024 to September 19, 2025 and may have accessed or acquired certain personal information stored within the system. On January 13, 2026, VillageCareMAX provided notice to affected individuals and posted notice on their website. The impacted data may include the following sensitive information:

  • Names
  • Social Security Numbers
  • Member Numbers
  • Health Information

The VillageCareMAX Data Breach

VillageCareMAX recently provided notice of the data breach. All of the information stolen is likely valuable and dangerous to affected victims. As is likely to be the case with the VillageCareMAX data breach, in previous cyberattacks, victims of data theft have noticed identity theft attempts ranging from fraudulent charges on bank accounts or credit cards, to unauthorized credit card applications, to medical services or government services ordered in their name, to their information being posted on the dark web, to a massive uptick in the number of spam text messages, calls and emails received.

Are you concerned that you might be affected by the VillageCareMAX data breach?

If you have concerns that you have been affected by this data breach, and/or have experienced suspicious activity since November 20, 2024, we would like to hear from you. Please complete the contact form on this page, send us an email at [email protected], or give us a call at (202) 470-3520.

    The following will ask for your contact information so that we may reach you to talk about potential claims. This information is for our records only and will not be shared. By continuing, you consent to the collection of this information for these limited purposes.


    Did you receive a notification that you were affected by the data breach?


    Would you like to join our newsletter to receive notifications about other investigations we're looking into, as well as updates on ongoing cases?

    By submitting this form, you consent to receive marketing, updates, and informative SMS messages from Migliaccio & Rathod LLP at the email and/or phone number provided. Consent is not a condition of purchase. Message & data rates may apply. Message frequency varies. Unsubscribe at any time by replying STOP or Reply HELP for help. Privacy Policy

    The lawyers at Migliaccio & Rathod LLP have years of experience in class action litigation against large corporations, including in cases involving data breaches such as this. More information about our current cases and investigations is available on our blog.

    Data Breach FAQ

    I received a notice that my information may have been involved in a data breach. What should I do?

    Take the notification seriously and read it carefully. It should outline what specific information was affected (e.g., name, Social Security number, legal case data). Even if you believe your risk is minimal, it’s best to take proactive steps to protect yourself.

    What immediate actions should I take?

    • Monitor your financial accounts – Regularly check your bank, credit card, and online accounts for unauthorized transactions.
    • Change your passwords – Update passwords for any accounts that may be connected to the breach. Avoid reusing old or similar passwords. Use a password manager if needed.
    • Set up two-factor authentication (2FA) – Enable 2FA on your email, banking, and other sensitive accounts to add an extra layer of protection.
    • Place a fraud alert or credit freeze – Contact one of the three major credit bureaus (Equifax, Experian, TransUnion) to place a fraud alert or freeze your credit report. This makes it harder for someone to open new accounts in your name.

    What is credit monitoring, and how should I use it?

    Credit monitoring tracks your credit report for changes or suspicious activity. If the organization that was breached offers this service for free, it’s highly recommended you enroll. These services can alert you quickly to potential fraud.

    How long do I need to stay vigilant?

    The effects of a data breach can surface months or even years later. Stay alert to signs of identity theft for at least 12–24 months. Keep an eye on your credit reports, mail, and any unfamiliar account activity.

    Who can I contact if I need help?

    Use the contact details provided in the breach notification. You can also report identity theft to the Federal Trade Commission at www.identitytheft.gov for recovery resources.