The Central Kansas Mental Health Center 2025 data breach was an unauthorized-access incident identified within the Salina-based behavioral-health provider's network on September 26, 2025. CKMHC's official notice confirms that an unauthorized individual entered the network and likely accessed files containing protected health information.
While the review was ongoing, an initial federal HHS OCR report listed 80,860 people. A later Texas Attorney General filing made during the completed file-review and individual-notification phase reports 37,610 people for the same event. LeakData uses the newer regulatory total, preserves the discrepancy, and imports no personal-data rows; importedRecordCount is zero.
How Was the CKMHC Breach Confirmed?
The primary source is the Notice of Data Security Incident published on Central Kansas Mental Health Center's official domain. It directly describes the discovery date, unauthorized network access, files containing protected health information, the outside cybersecurity investigation, technical measures, and planned notification of affected people.
The second source is the HHS OCR breach portal, which confirms the organization as a Healthcare Provider and classifies the event as a Hacking/IT Incident involving a Network Server. The third is the Texas Attorney General record published June 24, 2026. That newer filing supplies the affected fields, mailed notice, and final 37,610-person total; an Indiana Attorney General report also lists the same discovery sequence.
What Happened on September 26, 2025?
On or around September 26, CKMHC identified suspicious activity within its network. The organization activated its incident-response protocols, took the network offline, and engaged outside cybersecurity experts to investigate the nature and scope. The investigation found that an unauthorized individual entered the network and likely accessed sensitive files.
When the initial web notice was issued in November 2025, the file review was still underway and the organization had not yet determined which fields applied to which people. CKMHC said it would mail letters as valid addresses were identified after review. The breachDate field uses the official September 26 discovery date rather than constructing an unconfirmed start of actor access.
What Information Was Affected?
The later Texas regulatory record lists names, addresses, Social security numbers, driver's-license details, government identification such as passport or state-ID numbers, financial account or credit and debit card information, medical information, health-insurance information, and dates of birth. The combination is highly sensitive personal and protected health information.
The filing does not say that every field appeared for all 37,610 people. This entry therefore creates no subgroup counts and does not add undisclosed email addresses, passwords, or usernames. The official web notice confirms likely access to files; it does not say the data was publicly released, sold, or obtained by a named ransomware group.
Why Does the Entry Use 37,610 People?
The HHS OCR row dated November 25, 2025 shows 80,860 people during the early period when CKMHC said its file review was still in progress. The later consumer-notification record published by the Texas Attorney General on June 24, 2026 reports 37,610 in Total Number of Individuals Affected and 682 in Number of Texans Affected.
The pwnCount and totalRecords fields therefore use 37,610, the newer completed individual-notification total. This decision does not erase the federal row or create a separate incident; sourceNotes preserves both regulatory values and their dates. The value counts people in the final notification scope, not files, treatments, insurance claims, or data elements.
What Measures Did CKMHC Take?
The organization said it took the network offline, changed system and user passwords, restored systems, and notified law enforcement. It also deployed additional endpoint threat-detection tools within the network and worked with outside specialists on the investigation and file review.
No evidence of misuse had been found when the initial notice was issued. People with valid addresses received letters containing more incident detail, complimentary credit-monitoring and identity-protection services, and protective steps. The absence of known misuse does not guarantee that identity or healthcare fraud will not appear later.
What Should Affected People Do?
Notice recipients should activate the offered monitoring and identity-protection service within the stated enrollment period and review credit reports, bank and card activity, and health-insurance explanation-of-benefits statements for unfamiliar accounts or services. A suspicious entry should be reported through a previously known official channel for the relevant organization.
The combination of medical, financial, and identity information can make targeted scams convincing. Links in unexpected messages claiming to be from CKMHC, an insurer, bank, or public agency should not be opened directly; contact should begin through an official site or verified number. LeakData does not host, distribute, or provide search access to stolen personal or health information.