The Seltzer Firm; The University of Texas MD Anderson Cancer Center data breach: you may be owed a payment
If a The Seltzer Firm; The University of Texas MD Anderson Cancer Center letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.
Why you received this letter
The Seltzer Firm and The University of Texas MD Anderson Cancer Center represent a complex intersection of elite legal advocacy and world-renowned oncology care. MD Anderson Cancer Center is globally recognized as a premier academic medical institution dedicated to patient care, research, education, and prevention, meaning it handles vast volumes of highly sensitive protected health information (PHI) alongside detailed patient financial records. Concurrently, specialized legal entities like The Seltzer Firm manage confidential client files, corporate compliance data, proprietary research, and sensitive settlement or litigation records. Because of the critical, high-stakes nature of their operations, these organizations routinely collect, process, and store immense quantities of sensitive personal, medical, and financial data for patients, employees, and clients alike, making them prime targets for malicious cyber actors seeking high-value information. In 2025, a significant security incident involving The Seltzer Firm and The University of Texas MD Anderson Cancer Center was formally reported to the Maryland Attorney General's office. While the precise vectors of such sophisticated attacks vary, incidents targeting premier healthcare and legal entities typically involve unauthorized network intrusions, targeted ransomware deployment, or severe third-party vendor compromises. Because healthcare networks and legal databases house interconnected systems containing legacy data alongside modern electronic health record (EHR) platforms, attackers frequently exploit vulnerabilities in perimeter defenses or credential management protocols to gain persistent access to internal environments before exfiltrating critical databases. The exposure resulting from this breach compromises a devastating array of sensitive data categories, each carrying severe, long-term risks for affected individuals. Exposed protected health information, such as medical record numbers, diagnoses, treatment histories, and health insurance details, can be exploited by bad actors to commit medical fraud, fraudulently obtain prescription drugs, or disrupt ongoing patient care. Furthermore, if Social Security numbers, dates of birth, financial account details, or legal document files were accessed, victims face an immediate and elevated risk of identity theft, tax fraud, unauthorized credit openings, and complete financial account takeover. The unauthorized disclosure of such intimate personal details fundamentally shatters an individual's privacy and leaves them vulnerable to targeted phishing scams and social engineering attacks for years to come. Organizations handling healthcare and confidential professional data are bound by stringent regulatory frameworks, most notably the Health Insurance Portability and Accountability Act (HIPAA), alongside state data protection statutes and common-law duties of care. These legal frameworks mandate rigorous administrative, physical, and technical safeguards—such as robust encryption standards, multi-factor authentication, continuous network monitoring, and routine vulnerability assessments—to ensure the confidentiality, integrity, and availability of sensitive files. The occurrence of a widespread data breach strongly suggests a failure in these mandatory security protocols, indicating that the organization may have fallen short of its legal obligations to properly secure and defend its network infrastructure against foreseeable cyber threats. Receiving an official data breach notification letter from The Seltzer Firm or The University of Texas MD Anderson Cancer Center serves as formal legal confirmation that your private information was compromised due to inadequate corporate security measures. Under established legal principles, this notification establishes the necessary standing to initiate or participate in a class action lawsuit aimed at demanding accountability, securing financial compensation, and forcing organizational improvements in data protection practices. Importantly, affected individuals do not need to prove that they have already suffered direct financial loss or identity theft to pursue legal action; the mere exposure of private data constitutes a compensable injury. Our law firm handles these complex privacy cases on a strict contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Information the filing reports as involved
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Financial Account Number
What to do after the letter
Confirm the notice is genuine
A legitimate The Seltzer Firm; The University of Texas MD Anderson Cancer Center notice references the specific incident reported to the Maryland Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.
Keep the letter — it is your proof of connection
The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.
Protect your accounts and credit
Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.
Find out whether you have a claim
Whether the The Seltzer Firm; The University of Texas MD Anderson Cancer Center breach gives you a legal claim depends on the facts. A free, no-obligation case review will tell you where you stand — there is no cost and no commitment to find out.
This page summarizes a data breach reported to the Maryland Attorney General for informational purposes and is attorney advertising. It does not create an attorney-client relationship. DataBreachPayment.com does not provide legal advice through this page.