The Center for Life Resources 2025 data breach involved unauthorized access to the internal network of the community mental-health organization also known as Central Texas MHMR and the copying of files. The organization identified suspicious activity on November 17, 2025, and its investigation found that unauthorized access occurred on November 14 and 15.
Current Texas Attorney General record BR-0005197 reports that 26,055 people across the United States were affected, including 10,031 Texas residents. The possible scope includes identity, contact, financial, medical, and health-insurance information.
How Was the Center for Life Resources Breach Confirmed?
The primary incident source is the official notice published on Center for Life Resources' own domain. Issued by the organization, it describes discovery of unusual activity, steps to secure systems, an investigation with cybersecurity specialists, the November 14–15 access window, and files that were copied or potentially viewed.
The second official source is Texas Attorney General data security breach record BR-0005197. It identifies the organization as Central Texas MHMR dba Center for Life Resources at its Brownwood address and publishes the U.S. and Texas counts, notice method, and affected-data categories. ClaimDepot connects the company notice and regulatory records to the same event.
What Happened on November 14 and 15, 2025?
The organization detected unusual activity in its internal network on November 17, took steps to secure systems, and said services to clients were not disrupted. An investigation with outside cybersecurity specialists determined that an unauthorized actor accessed the network on November 14 and 15 and copied or may have viewed certain files.
The public official notice does not establish the initial entry method, exploited vulnerability, ransom demand, or actor identity. Secondary reporting says a ransomware group claimed the event in December 2025, but that claim has not been confirmed in official records and is not used as evidence for data fields or incident scope.
What Identity and Financial Information Was Affected?
The Texas Attorney General lists possible personal fields as names, addresses, Social security numbers, driver's license numbers, government-issued identifiers such as passports or state IDs, and dates of birth. The scope varied by person, and the sources do not say every file contained every category.
Financial information is also a confirmed broad category and can include account numbers or credit and debit card numbers. The official record does not specify which financial field applied to which individual. These data can raise the risks of identity theft, new-account fraud, payment fraud, and targeted social engineering.
What Health Information Was Affected?
Center for Life Resources provides mental-health, intellectual and developmental disability, substance-use, and related community services. The Texas record confirms medical information and health-insurance information within the incident scope. These categories are sensitive because they may reveal a care relationship or connection to a health plan.
Public sources do not separately publish diagnoses, treatments, prescriptions, laboratory results, physician names, medical-record numbers, or service dates as confirmed fields. Those details should not be assumed. People with health information involved should regularly review insurance explanations and provider records for unfamiliar services, claims, or changes.
How Many People Were Affected?
Texas Attorney General record BR-0005197 publishes an exact nationwide total of 26,055 people and a Texas subset of 10,031. The Texas figure is included in the nationwide population and has not been added on top of it. Older public summaries saying an exact total had not been disclosed are superseded by the current Texas record.
The organization's detailed notice gives November 14–15, 2025 as the unauthorized-access window. Because a broader date field in the Texas portal does not fully align with that narrative, the company's detailed forensic finding is used for the incident window. The Texas record is used for the affected-person total and data categories, while its conflicting end-date field is not interpreted as the duration of technical access.
What Should Affected People Do?
Notice recipients should check their letter for the data fields involved and review credit reports, bank and card activity, health-insurance explanations, and healthcare records for unfamiliar accounts, transactions, or services. When a Social Security number was involved, a free credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate.
Identification numbers, passwords, payments, and verification codes should not be shared through unexpected messages claiming to represent Center for Life Resources, a health plan, or a financial institution. Use known official channels instead of links in the message. An individual's authentic notification letter is the primary source for person-specific fields and protection options.