All Breaches
March 2, 2025 Verified Sensitive Record Healthcare

Counseling Center of Wayne & Holmes Counties 2025 Data Breach

The Counseling Center of Wayne & Holmes Counties 2025 data breach involved unauthorized access to and data removal from a server belonging to the Ohio mental health organization. According to the official notice, an unauthorized entity likely accessed one server on March 2, 2025 and took information from the systems on March 3. A third-party service provider alerted the center to suspicious activity that same day.

The center isolated systems it believed were affected, reset account credentials, and worked with data-security specialists on a forensic investigation. The U.S. Department of Health and Human Services Office for Civil Rights portal lists 83,354 affected people.

How Was the Counseling Center Incident Verified?

The primary source is the “Notice of Data Incident” PDF published in the organization's name. It confirms the March 2 access, March 3 data removal and alert, rapid containment measures, completion of the scope review on December 9, possible data fields, and no evidence that any individual's personal information was used for identity theft or fraud.

The second source is the HHS/OCR federal row reported February 9, 2026 for 83,354 people. ClaimDepot's incident page connects the same organization PDF, Massachusetts and Maine filings, and HHS total. General risk language on the secondary page is not used to add financial-account fields, a threat-actor name, or malware absent those details in the official text.

Verified Incident Timeline

The forensic investigation found that an unauthorized entity likely accessed one Counseling Center server on March 2, 2025 and took information from the systems on March 3. The incident date is based on the earliest technical activity that can be verified from public sources. This separates the first possible access from the day the organization learned of the event.

After the March 3 alert, the center isolated systems, reset credentials, and engaged outside specialists. Completion of the affected-data analysis on December 9, 2025 does not mean the incident began that day; it is the end of the lengthy scope review used to identify people for notice. February 9, 2026 is the HHS report date.

What Information May Have Been Involved?

The official notice lists names, dates of birth, Social security numbers, driver's license or state identification numbers, health insurance information, medical condition information, treatment provider names, medical record numbers, treatment costs, and diagnosis or treatment information, with the combination varying by person. The data categories rely only on this organization list.

The notice explicitly says not every disclosed category is relevant to every person. It confirms that information was taken from systems while also stating there is no evidence that any individual's information was used for identity theft or fraud. This distinction separates confirmed data removal from confirmed later misuse.

How Should the Affected-Person Count Be Interpreted?

83,354 is the official affected-person count in the HHS/OCR portal; it is not a number of servers, files, data rows, or residents of one state. Small local subsets in Massachusetts, Maine, and other state filings are not added to this federal total. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.

When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.

Identity and Medical Privacy Risks

Social security numbers, dates of birth, and government identifiers can increase the risk of fraudulent accounts, tax fraud, or bypassed identity checks. Recipients can monitor credit reports and new-account inquiries and consider a fraud alert or credit freeze. Unexpected requests invoking the center should be separately verified through a known official channel.

Medical conditions, treatment providers, medical record numbers, treatment costs, and diagnosis or treatment information create persistent privacy and medical identity-theft risks. Users should review explanations of benefits and unfamiliar healthcare services and report care they did not receive to the insurer and provider. Sensitive health information should not be disclosed in unsolicited calls or messages.

Organization Response and User Actions

The Counseling Center said it isolated systems it believed were affected, reset account credentials, and worked with data-security and privacy professionals to determine scope. It also said it further strengthened existing safeguards and that the swift response minimized additional unauthorized activity.

Users can review free annual credit reports, report suspicious activity to financial institutions, and monitor health insurance records. If identity theft is suspected, they can contact the Federal Trade Commission or relevant state authority. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope.

83.4 Thousand
Affected Accounts
10
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

10
Names
Dates of birth
Social security numbers
Driver's license or state id numbers
Health insurance information
Medical condition information
Treatment provider names
Medical record numbers
Treatment cost information
Diagnosis or treatment information

Additional Information

Added DateJuly 27, 2026
Breach DateMarch 2, 2025
Domainccwhc.org
SourceOfficial Counseling Center notice, HHS/OCR breach report, and independent incident reporting
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information