All Breaches
December 24, 2024 Verified Sensitive Record Healthcare

Denton County MHMR Center 2024 Data Breach

The Denton County MHMR Center 2024 data breach was unauthorized access to the organization's network from December 24 through December 25, 2024. The Center's updated official notice confirms that certain information on the network was accessed by an unauthorized party. The US Department of Health and Human Services Office for Civil Rights records it as a network-server incident affecting 108,967 current and former patients.

Depending on the person, affected information may include names, addresses, patient identification numbers, dates of birth, diagnoses, medical histories, medical record numbers, treatment, laboratory data, treating doctors, medications, vaccinations, health insurance information, and biometric identifiers. The organization found no evidence of misuse at notification. LeakData imported no patient data, and importedRecordCount is zero.

How Was the Denton County MHMR Center Breach Confirmed?

The primary evidence is the data-security notice on the Center's own domain, updated December 30, 2025, together with its linked initial notice PDF. It says information on the network was accessed by an unauthorized party between December 24 and December 25, 2024. This finding establishes that protected data entered the access scope; it is not merely evidence of an outage or unexplained activity.

The HHS OCR row classifies Denton MHMR Center as a Healthcare Provider, the event as a Hacking/IT Incident, and the information location as Network Server; it reports 108,967 affected people. The HIPAA Journal independently compared the official notice, federal record, and updated field list. The three sources align on the organization, access window, and scope.

What Was the Incident and Review Timeline?

The Center identified unusual network activity on or around December 24, 2024, secured the environment, and opened an investigation with third-party specialists. The review determined that the unauthorized party had access for a limited period from December 24 through December 25. The breachDate field uses December 24, the first day of that confirmed window.

When the organization published an initial substitute notice on February 21, 2025, its file and population review was still underway. It determined the detailed scope of potential data elements on October 10, reported the event to HHS OCR on November 5, and later notified state attorneys general. The web notice was updated December 30 to reflect credit-monitoring and identity-protection services.

What Patient Information Was Affected?

The current official list includes names, addresses, patient identification numbers, dates of birth, diagnoses, medical histories, medical record numbers, medical treatment, laboratory information, treating doctors' names, medications, vaccinations, medical insurance information, and biometric identifiers. dataClasses follows this completed review; it does not assume that every field applied to every person.

The February PDF, published before the review was complete, also identified Social Security and bank-account numbers as possible fields. The updated December page supplies the detailed results of the completed analysis and does not repeat those two elements. LeakData therefore uses the newer, specific list and does not add Social Security or bank-account numbers to the final data classes, while preserving the source evolution in this explanation.

What Does the 108,967-Person Scope Mean?

The pwnCount and totalRecords fields use the current HHS OCR value of 108,967 people. The HIPAA Journal identifies the population as current and former patients. The figure counts individuals in the notification scope, not copied files, rows, or fields; one person may have multiple types of information involved.

The official text confirms access to certain information but does not say that files were removed, publicly released, or sold. The entry therefore classifies the unauthorized access as a real breach without adding unsupported claims about an exfiltration method or actor identity. It likewise does not attribute every listed data class to all 108,967 people.

What Measures Did the Organization Take?

The Center secured its network after finding the unusual activity and engaged specialists to investigate. It later worked with third-party cybersecurity experts to implement additional network protections and reviewed and enhanced its data-protection policies and procedures. The initial notice also says law enforcement was notified.

The updated notice states that potentially affected individuals were offered complimentary credit monitoring and identity-protection services. At notification, the Center said it had no evidence of information misuse connected to the incident. The absence of observed misuse does not eliminate the longer-term risk presented by sensitive health and biometric information.

What Should Affected Patients Do?

Notice recipients can use the Center's dedicated assistance line to confirm eligibility and enrollment deadlines for the offered credit-monitoring and identity-protection services. Credit reports, financial statements, and health-insurance explanations of benefits should be reviewed regularly for unfamiliar accounts, transactions, doctors, laboratory services, or insurance claims.

If an unknown care, prescription, vaccination, or insurance entry appears, contact the provider and insurer through known official channels. Because biometric data cannot be changed like a password, unexpected identity-verification requests deserve particular caution. LeakData does not publish accessed patient records; it provides verified breach metadata and practical follow-up guidance.

109 Thousand
Affected Accounts
15
Data Types
High
Severity
Yes
Verification

Exposed Data Types

15
Protected health information
Names
Physical addresses
Patient identification numbers
Dates of birth
Diagnoses
Medical histories
Medical record numbers
Medical treatment information
Laboratory information
Treating doctors
Medication information
Vaccination information
Health insurance information
Biometric identifiers

Additional Information

Added DateJuly 27, 2026
Breach DateDecember 24, 2024
Domaindentonmhmr.org
SourceOfficial notice confirming unauthorized network access
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information