[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2itac9bd1nz7h":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"6a70abe6b0443f4868a64089","HarborOhio2025","Harbor Ohio 2025 Data Breach","harbor-ohio-2025","harbor.org","2025-07-25T00:00:00.000Z","2026-08-03T14:55:34.210Z","Official Harbor notice, HHS OCR, and independent breach reporting","https:\u002F\u002Fd3kvsa3kfj2pqv.cloudfront.net\u002Fuploads\u002Fdocuments\u002FWebsite-Data-Incident-Notice-Sept-30-2025.pdf",[14,16],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",216000,"known",null,"people","High",[23,24,25,26,27,28,29,30,31,32,33],"Names","Physical addresses","Dates of birth","Social security numbers","Driver's license numbers","Government issued IDs","Financial account information","Health insurance information","Diagnoses","Treatment information","Medical information","\u003Cp>\u003Cstrong>The 2025 Harbor Ohio data breach\u003C\u002Fstrong> involved unauthorized access to the mental-health provider's computer network between July 25 and August 1, 2025. Harbor said the attacker took certain files. The U.S. Department of Health and Human Services breach record reports 216,000 affected people.\u003C\u002Fp>\u003Cp>The incident concerns the harbor.org network operated by Harbor, a provider of mental-health and addiction-treatment services in Ohio. Breaches involving similarly named organizations and Harbor's smaller June 2025 email incident are not part of this record.\u003C\u002Fp>\u003Ch2>How did the Harbor data breach happen?\u003C\u002Fh2>\u003Cp>Harbor detected suspicious activity on its computer network on August 1, 2025. Its investigation found that an unauthorized person accessed the network and took certain files between July 25 and August 1.\u003C\u002Fp>\u003Cp>The organization did not disclose how the attacker gained initial access or whether a specific software vulnerability was exploited. The record therefore does not assign an unconfirmed technical cause.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed fields included names, addresses, dates of birth, Social Security numbers, driver's license numbers, or other state identification numbers.\u003C\u002Fp>\u003Cp>Financial-account information, health-insurance information, medical diagnosis and treatment information, and clinical information may also have been involved for some people. Not every category applied to every affected individual.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The HHS Office for Civil Rights record for the network-server incident reports 216,000 affected individuals. This total was not combined with Harbor's separate email incident reported on June 20, 2025, which affected 2,703 people.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers combined with dates of birth and addresses can increase the risk of identity theft or fraudulent credit applications. Driver's-license and financial-account information may also be used in impersonation or fraud attempts.\u003C\u002Fp>\u003Cp>Health and insurance details can help an attacker craft targeted messages that appear to refer to a real treatment or provider relationship. Unexpected healthcare, payment, or insurance requests should be verified through an independent official channel.\u003C\u002Fp>\u003Ch2>How did Harbor respond?\u003C\u002Fh2>\u003Cp>Harbor said it launched an investigation, conducted a comprehensive review of affected files, and notified appropriate individuals. People whose information was involved were offered complimentary credit monitoring and identity-protection services.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, financial accounts, health-insurance statements, and medical bills for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>For an unexpected email or call claiming to come from Harbor or a healthcare organization, recipients should use contact details from the organization's official website rather than a link or number supplied in the message.\u003C\u002Fp>","","Harbor Ohio Data Breach (216 Thousand People Affected)","The Harbor Ohio data breach affected 216,000 people and may have exposed identity, financial, insurance, and medical information.","\u002Fuploads\u002Flogo\u002Fharbor-ohio-official.png",false,{"name":41,"sector":42,"country":43,"website":44,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":19},"Harbor","Healthcare","United States","https:\u002F\u002Fwww.harbor.org\u002F"]