4 behavioral health data breaches making headlines

Advertisement

Behavioral health providers have reported a string of data breaches in recent months, ranging from a Texas breach affecting more than a quarter-million patients to smaller incidents tied to insider access and compromised email accounts.

Together, the reports reflect two persistent vulnerabilities for the sector: external actors probing networks and email systems, and internal workforce access to sensitive patient records.

These four incidents underscore how missteps expose sensitive behavioral health and substance use data — often the most stigmatized category of patient information — even as providers respond with credit monitoring, expanded authentication and stricter access controls.

Here are four breaches to know:

  1. Colorado. Lakewood, Colo.-based NAS Recovery Solutions disclosed a data breach affecting up to 7,000 current and former clients after workforce members downloaded client information without authorization, exposing first and last names, dates of birth and telephone numbers. Because the organization provides substance use disorder treatment, it said it could be inferred that the affected individuals were receiving substance use disorder treatment — raising the stakes given the added privacy protections tied to that category of care. The provider hasn’t disclosed why staff downloaded the data or what disciplinary action followed, but said it has since tightened access controls and retrained staff on HIPAA compliance.
  2. Nebraska. Hastings, Neb.-based Wabi Sabi Behavioral Health Center identified unauthorized access affecting an as-yet-undisclosed number of employees after an attacker sought to divert payroll payments. The attacker sought to change employees’ account details to redirect payroll payments to attacker-controlled accounts on June 15, and the unauthorized access was flagged the same day. Employee names, addresses and Social Security numbers may have been viewed or copied, and affected staff have been offered credit monitoring. The state attorney general has been notified, though the number of people affected hasn’t been made public.
  3. Arizona. Phoenix-based Southwest Behavioral and Health Services reported a hacking and IT incident involving email systems that affected 2,316 individuals, with notification submitted to HHS in May. A forensic investigation determined that six employee email accounts were compromised. The organization hasn’t disclosed exactly what information was exposed, and it said no evidence has been identified to suggest misuse of the affected data.
  4. Texas. Dallas-based North Texas Behavioral Health Authority reported a data breach affecting 285,086 individuals, making it the sixth largest breach reported to the Office for Civil Rights in 2026. An unauthorized third party accessed the organization’s network between Oct. 13 and 15, and a review confirmed in January that some exposed files included Social Security numbers. Notification letters went out beginning March 6, and the organization is offering credit monitoring while it has since reset passwords, expanded multi-factor authentication and deployed endpoint detection and response tools. No threat actor has claimed responsibility, though some law firms are reportedly weighing class-action suits.

At the Becker's Fall Behavioral Health Summit, taking place November 4–5 in Chicago, behavioral health leaders and executives will explore strategies for expanding access to care, integrating services, addressing workforce challenges and leveraging innovation to improve outcomes across the behavioral health continuum. Apply for complimentary registration now.

Register to Attend Webinar

Reconsider What’s Possible: Enterprise RCM and the Pro-Fee Practice

Tuesday, July 28
11:00 AM - 12:00 PM CDT

Presenters: Garett Kreitz, Med-MetrixJohn Stefanowicz, Med-Metrix

Advertisement

Next Up in Legal

Advertisement