The Counseling Center of Wayne & Holmes Counties 2025 data breach involved unauthorized access to and data removal from a server belonging to the Ohio mental health organization. According to the official notice, an unauthorized entity likely accessed one server on March 2, 2025 and took information from the systems on March 3. A third-party service provider alerted the center to suspicious activity that same day.
The center isolated systems it believed were affected, reset account credentials, and worked with data-security specialists on a forensic investigation. The U.S. Department of Health and Human Services Office for Civil Rights portal lists 83,354 affected people.
How Was the Counseling Center Incident Verified?
The primary source is the “Notice of Data Incident” PDF published in the organization's name. It confirms the March 2 access, March 3 data removal and alert, rapid containment measures, completion of the scope review on December 9, possible data fields, and no evidence that any individual's personal information was used for identity theft or fraud.
The second source is the HHS/OCR federal row reported February 9, 2026 for 83,354 people. ClaimDepot's incident page connects the same organization PDF, Massachusetts and Maine filings, and HHS total. General risk language on the secondary page is not used to add financial-account fields, a threat-actor name, or malware absent those details in the official text.
Verified Incident Timeline
The forensic investigation found that an unauthorized entity likely accessed one Counseling Center server on March 2, 2025 and took information from the systems on March 3. The incident date is based on the earliest technical activity that can be verified from public sources. This separates the first possible access from the day the organization learned of the event.
After the March 3 alert, the center isolated systems, reset credentials, and engaged outside specialists. Completion of the affected-data analysis on December 9, 2025 does not mean the incident began that day; it is the end of the lengthy scope review used to identify people for notice. February 9, 2026 is the HHS report date.
What Information May Have Been Involved?
The official notice lists names, dates of birth, Social security numbers, driver's license or state identification numbers, health insurance information, medical condition information, treatment provider names, medical record numbers, treatment costs, and diagnosis or treatment information, with the combination varying by person. The data categories rely only on this organization list.
The notice explicitly says not every disclosed category is relevant to every person. It confirms that information was taken from systems while also stating there is no evidence that any individual's information was used for identity theft or fraud. This distinction separates confirmed data removal from confirmed later misuse.
How Should the Affected-Person Count Be Interpreted?
83,354 is the official affected-person count in the HHS/OCR portal; it is not a number of servers, files, data rows, or residents of one state. Small local subsets in Massachusetts, Maine, and other state filings are not added to this federal total. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.
When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.
Identity and Medical Privacy Risks
Social security numbers, dates of birth, and government identifiers can increase the risk of fraudulent accounts, tax fraud, or bypassed identity checks. Recipients can monitor credit reports and new-account inquiries and consider a fraud alert or credit freeze. Unexpected requests invoking the center should be separately verified through a known official channel.
Medical conditions, treatment providers, medical record numbers, treatment costs, and diagnosis or treatment information create persistent privacy and medical identity-theft risks. Users should review explanations of benefits and unfamiliar healthcare services and report care they did not receive to the insurer and provider. Sensitive health information should not be disclosed in unsolicited calls or messages.
Organization Response and User Actions
The Counseling Center said it isolated systems it believed were affected, reset account credentials, and worked with data-security and privacy professionals to determine scope. It also said it further strengthened existing safeguards and that the swift response minimized additional unauthorized activity.
Users can review free annual credit reports, report suspicious activity to financial institutions, and monitor health insurance records. If identity theft is suspected, they can contact the Federal Trade Commission or relevant state authority. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope.