Behavioral health providers have reported a string of data breaches in recent months, ranging from a Texas breach affecting more than a quarter-million patients to smaller incidents tied to insider access and compromised email accounts.
Together, the reports reflect two persistent vulnerabilities for the sector: external actors probing networks and email systems, and internal workforce access to sensitive patient records.
These six incidents underscore how missteps expose sensitive behavioral health and substance use data — often the most stigmatized category of patient information — even as providers respond with credit monitoring, expanded authentication and stricter access controls.
Here are six breaches to know:
- Maine. Bangor, Maine-based Cornerstone Behavioral Healthcare discovered May 26, 2026, that a breach of certain protected health information occurred as a result of a ransomware attack. Cornerstone believes less than 10% of the data in the affected computers and servers may have been encrypted before it stopped the attack. The organization determined that PHI and/or personal information concerning 2,830 individuals may have been compromised. On July 22, 2026, Cornerstone’s continued investigation revealed that a log of appointment reminders for an additional 12,000 individuals may have been viewed or accessed during the ransomware attack. The log included patient names, dates of birth, appointment times and reminders of documentation due. Cornerstone wiped the affected computers, purchased new computers for its staff and implemented additional security measures.
- California. Bakersfield, Calif.-based Kern Psychiatric Health and Wellness Center reported that certain data was accessed without authorization after unusual activity was discovered on its management company’s computer network. Genesis Healthcare Management, discovered the unusual activity June 22, 2026, and began an investigation with third-party specialists. The investigation determined certain files on its network, which houses certain Kern Psychiatric Health and Wellness Center data, were accessed without authorization. The center said it is not aware of any fraud or unauthorized publication of information resulting from the incident and has no reason to believe the information will be misused.
- Colorado. Lakewood, Colo.-based NAS Recovery Solutions disclosed a data breach affecting up to 7,000 current and former clients after workforce members downloaded client information without authorization, exposing first and last names, dates of birth and telephone numbers. Because the organization provides substance use disorder treatment, it said it could be inferred that the affected individuals were receiving substance use disorder treatment — raising the stakes given the added privacy protections tied to that category of care. The provider hasn’t disclosed why staff downloaded the data or what disciplinary action followed, but said it has since tightened access controls and retrained staff on HIPAA compliance.
- Nebraska. Hastings, Neb.-based Wabi Sabi Behavioral Health Center identified unauthorized access affecting an as-yet-undisclosed number of employees after an attacker sought to divert payroll payments. The attacker sought to change employees’ account details to redirect payroll payments to attacker-controlled accounts on June 15, and the unauthorized access was flagged the same day. Employee names, addresses and Social Security numbers may have been viewed or copied, and affected staff have been offered credit monitoring. The state attorney general has been notified, though the number of people affected hasn’t been made public.
- Arizona. Phoenix-based Southwest Behavioral and Health Services reported a hacking and IT incident involving email systems that affected 2,316 individuals, with notification submitted to HHS in May. A forensic investigation determined that six employee email accounts were compromised. The organization hasn’t disclosed exactly what information was exposed, and it said no evidence has been identified to suggest misuse of the affected data.
- Texas. Dallas-based North Texas Behavioral Health Authority reported a data breach affecting 285,086 individuals, making it the sixth largest breach reported to the Office for Civil Rights in 2026. An unauthorized third party accessed the organization’s network between Oct. 13 and 15, and a review confirmed in January that some exposed files included Social Security numbers. Notification letters went out beginning March 6, and the organization is offering credit monitoring while it has since reset passwords, expanded multi-factor authentication and deployed endpoint detection and response tools. No threat actor has claimed responsibility, though some law firms are reportedly weighing class-action suits.
At the Becker's Fall Behavioral Health Summit, taking place November 4–5 in Chicago, behavioral health leaders and executives will explore strategies for expanding access to care, integrating services, addressing workforce challenges and leveraging innovation to improve outcomes across the behavioral health continuum. Apply for complimentary registration now.
