What Happened?
On or about July 17, 2025, Blue Fish Pediatrics ("Blue Fish") detected unauthorized activity on its computer systems. Upon detection, Blue Fish immediately contained the incident and commenced an investigation into the incident with the assistance of cybersecurity professionals. The investigation determined on May 4, 2026 that an unauthorized actor accessed Blue Fish's systems from July 11 to July 17, 2025, wherein the unauthorized party accessed or acquired a limited number of files containing personal information.
On June 17, 2026, Blue Fish posted a notice of the incident to its website. The following day, an entry for the breach appeared on the reporting site for the Texas Attorney General. Blue Fish is notifying affected individuals via U.S. Mail.