
Evoke Wellness at Hilliard 2025 Data Breach (1.6 Thousand People Affected)
The 2025 Evoke Wellness at Hilliard data breach was a security incident announced after unauthorized activity was detected in the network of the addiction-treatment center operated by OCAT, LLC. The organization's notice says some patient information may have been accessed without authorization.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the event as an unauthorized-access/disclosure incident involving electronic medical records and reported 1,629 affected individuals.
Verified Incident TimelineEvoke Wellness at Hilliard identified potential unauthorized activity in its network on August 7, 2025, and began investigating the cause and scope. The organization finalized the list of people to notify on February 20, 2026; the consumer letter is dated February 27, 2026.
What Information May Have Been Affected?The affected information may vary by person. The official notice lists names, addresses, dates of birth, Social Security numbers, driver's-license information, and credit-card information.
How the Organization RespondedThe organization says it confirmed the security of its systems and implemented additional security measures intended to reduce the risk of a similar incident. The notice says there was no evidence at that time that the personal information had been misused.
What Should Affected People Do?Notice recipients should regularly review credit-card activity, account statements, and credit reports for unfamiliar transactions. People whose Social Security or driver's-license information was affected may consider a fraud alert or credit freeze based on their circumstances.