The The Seltzer Firm; The University of Texas MD Anderson Cancer Center Data Breach: Incident Facts and Free Case Review
The Seltzer Firm and The University of Texas MD Anderson Cancer Center represent a complex intersection of elite legal advocacy and world-renowned oncology care. MD Anderson Cancer Center is globally recognized as a premier academic medical institution dedicated to patient care, research, education, and prevention, meaning it handles vast volumes of highly sensitive protected health information (PHI) alongside detailed patient financial records. Concurrently, specialized legal entities like The Seltzer Firm manage confidential client files, corporate compliance data, proprietary research, and sensitive settlement or litigation records. Because of the critical, high-stakes nature of their operations, these organizations routinely collect, process, and store immense quantities of sensitive personal, medical, and financial data for patients, employees, and clients alike, making them prime targets for malicious cyber actors seeking high-value information.
Received a The Seltzer Firm; The University of Texas MD Anderson Cancer Center notification letter? Find out in minutes if you qualify for compensation.
Free case review- State
- Maryland
- Reported
- March 12, 2025
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Financial Account Number
In 2025, a significant security incident involving The Seltzer Firm and The University of Texas MD Anderson Cancer Center was formally reported to the Maryland Attorney General's office. While the precise vectors of such sophisticated attacks vary, incidents targeting premier healthcare and legal entities typically involve unauthorized network intrusions, targeted ransomware deployment, or severe third-party vendor compromises. Because healthcare networks and legal databases house interconnected systems containing legacy data alongside modern electronic health record (EHR) platforms, attackers frequently exploit vulnerabilities in perimeter defenses or credential management protocols to gain persistent access to internal environments before exfiltrating critical databases.
The exposure resulting from this breach compromises a devastating array of sensitive data categories, each carrying severe, long-term risks for affected individuals. Exposed protected health information, such as medical record numbers, diagnoses, treatment histories, and health insurance details, can be exploited by bad actors to commit medical fraud, fraudulently obtain prescription drugs, or disrupt ongoing patient care. Furthermore, if Social Security numbers, dates of birth, financial account details, or legal document files were accessed, victims face an immediate and elevated risk of identity theft, tax fraud, unauthorized credit openings, and complete financial account takeover. The unauthorized disclosure of such intimate personal details fundamentally shatters an individual's privacy and leaves them vulnerable to targeted phishing scams and social engineering attacks for years to come.
Organizations handling healthcare and confidential professional data are bound by stringent regulatory frameworks, most notably the Health Insurance Portability and Accountability Act (HIPAA), alongside state data protection statutes and common-law duties of care. These legal frameworks mandate rigorous administrative, physical, and technical safeguards—such as robust encryption standards, multi-factor authentication, continuous network monitoring, and routine vulnerability assessments—to ensure the confidentiality, integrity, and availability of sensitive files. The occurrence of a widespread data breach strongly suggests a failure in these mandatory security protocols, indicating that the organization may have fallen short of its legal obligations to properly secure and defend its network infrastructure against foreseeable cyber threats.
Receiving an official data breach notification letter from The Seltzer Firm or The University of Texas MD Anderson Cancer Center serves as formal legal confirmation that your private information was compromised due to inadequate corporate security measures. Under established legal principles, this notification establishes the necessary standing to initiate or participate in a class action lawsuit aimed at demanding accountability, securing financial compensation, and forcing organizational improvements in data protection practices. Importantly, affected individuals do not need to prove that they have already suffered direct financial loss or identity theft to pursue legal action; the mere exposure of private data constitutes a compensable injury. Our law firm handles these complex privacy cases on a strict contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Received the The Seltzer Firm; The University of Texas MD Anderson Cancer Center notification letter? The The Seltzer Firm; The University of Texas MD Anderson Cancer Center case file tracks this filing.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Maryland Attorney General filing
Related data breach cases
- St. Joseph College of Maine
- St. Joseph College of Maine
- VUC, Inc.
- Open Door Capital, LLC
- Clarke Nicolini & Associates, Ltd.
- Crown Health Care Laundry Services
- OrthoMinds, LLC
- CSG Consultants
- CSG Consultants
- Open Door Capital, LLC
- OrthoMinds, LLC
- Crown Health Care Laundry Services
- Kinsey's Archery Products, Inc.; VUC, Inc.
- VUC, Inc.