The Averhealth 2025 data breach was discovered after the behavioral-health and substance-use-monitoring company detected unusual activity in Avertest's email environment on January 20, 2026. According to the official incident page, an unauthorized party accessed the network from December 19, 2025 through January 21, 2026 and may have accessed or acquired files containing personal or health information.
The U.S. Department of Health and Human Services Office for Civil Rights lists the Averhealth Holdings event as a Hacking/IT Incident affecting 9,909 people. LeakData imported no person or patient rows, and importedRecordCount is zero. This page describes only verified event metadata from the official company notice and regulatory records.
How Was the Averhealth Breach Confirmed?
The primary source is the Data Incident page on Averhealth's own domain. The company notice directly states the access window, discovery and review dates, possible affected fields, notification process, and complimentary credit monitoring offered to people whose Social security numbers were involved.
The second confirmation is HHS OCR's breach report, which identifies the entity as a healthcare provider, classifies the event as a hacking/IT incident involving email, and reports 9,909 affected individuals. Massachusetts' official consumer-notice filing also supports the January 20 discovery, May 6 scope result, 12 months of Kroll monitoring, and dedicated response line.
When Did the Unauthorized Access Occur?
Averhealth detected unusual activity in Avertest's email environment on January 20, immediately secured the environment, and began a comprehensive investigation with external cybersecurity professionals. The investigation found that the unauthorized party accessed the network during the period from December 19, 2025 through January 21, 2026.
The breachDate field uses December 19, 2025, the first day of the verified access range, rather than conflating it with discovery. The official sources do not identify the attacker, intrusion method, or a ransomware group. Potential file access or acquisition was reported, but there is no verified claim in the sources that the information was published online.
When Were the Review and Notifications Completed?
The organization conducted a lengthy technical investigation and manual review to identify potentially affected files. On May 6, 2026, Averhealth determined that certain personal information may have been subject to unauthorized access or acquisition and began mailing letters on or about July 2 to potentially affected people for whom it had addresses.
HHS's 9,909-person entry is the authoritative public total. Jurisdiction-specific figures, such as the number of Massachusetts residents, are not substituted for the national count. The company said it had no evidence of identity theft or financial fraud related to the incident; that finding does not eliminate risk or guarantee that misuse will never occur.
What Identity and Financial Information May Have Been Affected?
Depending on the person, files may contain a name, date of birth, driver's-license number, digital or electronic signature, and Social Security number. Minor status and patient-account numbers also appear among the possible fields. This combination creates substantial exposure to identity theft, fraudulent accounts, signature misuse, and targeted social engineering.
The official page does not say every field was present for all 9,909 people and provides no field-level counts. Averhealth said credit monitoring was offered to people whose Social security numbers were impacted, which does not mean every person's SSN was involved. Payment-card and bank-account numbers are not added because the source does not confirm them.
What Health Information Was Involved?
Possible health data includes clinical information, diagnosis, a health-insurance policy-related number, medical cost, dates of service, medical history, provider name, medical-record number, treatment or procedure information, and mental or physical condition. These categories are sensitive for medical-identity fraud and loss of health privacy.
Averhealth provides substance-use monitoring services for courts and treatment programs, but the official incident page does not say a specific diagnosis, test result, or program participation was exposed for every person. LeakData stays within the source's list of possibilities and does not infer that complete medical files or every listed field were involved for everyone.
What Should Affected People Do?
Recipients should review credit reports, financial accounts, health-insurance explanation-of-benefits statements, and medical-service histories for unfamiliar activity. If an unknown account, inquiry, provider, treatment, or cost appears, the relevant organization should be contacted through a verified channel; a fraud alert or free credit freeze may also be appropriate.
Averhealth announced a dedicated 844-959-7153 response line for questions and affected-status checks, and provided complimentary monitoring to people whose SSNs were involved. Identity or health information should not be shared through unexpected links or calls. LeakData does not host, distribute, or make searchable email files, patient records, SSNs, or clinical information.