All Breaches
October 13, 2025 Verified Sensitive Record Healthcare

North Texas Behavioral Health Authority 2025 Data Breach

The North Texas Behavioral Health Authority 2025 data breach involved unauthorized access to the NTBHA network beginning on October 13, 2025 and continuing through October 15. The organization coordinates mental-health and substance-use services. The current record maintained by the US Department of Health and Human Services Office for Civil Rights shows that 285,086 people were affected.

The investigation determined that files containing patient information may have been viewed or acquired by the unauthorized party. The public substitute notice did not publish a detailed field list; Social security numbers were confirmed as exposed for some people. LeakData adds no inferred clinical fields, imports no personal records, and importedRecordCount is zero.

How Was the Breach Confirmed?

NTBHA identified unauthorized activity in its computer systems around October 15, 2025 and began investigating its nature. The review confirmed that an unauthorized third party accessed the network from October 13 through October 15. The presence of patient information in affected files and the federal HHS report establish a genuine healthcare-data breach.

HHS OCR lists the event as a Hacking/IT Incident, the information location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal compared the federal entry with the substitute notice and corroborated the access window, file review, and scope of 285,086 people. Because the sources do not make a definitive exfiltration finding, this entry does not describe data theft as confirmed.

What Was the Incident and Notification Timeline?

The breachDate field uses October 13, 2025, the first confirmed day of access. The activity was detected two days later and access ended on October 15. The organization spent roughly three months reviewing file contents and determining which people may have been affected; the discovery date is not substituted for the earlier start date.

NTBHA confirmed on January 7, 2026 that some files contained personal information and began mailing notices on March 6. The HHS row carries the same federal submission date and a total of 285,086 people. Independent reporting published in April matched the dates and scope in the organization's disclosure with the regulatory entry.

What Information Was Affected?

The classes confirmed by the public disclosure are personal information, protected health information, and Social security numbers for some people. The sources do not enumerate names, addresses, birth dates, diagnoses, treatments, insurance, or account details. The dataClasses list therefore contains only the three high-level categories expressly supported by the evidence.

The term protected health information confirms that healthcare data within HIPAA scope was involved, but it does not mean a particular clinical field was present for every victim. Social security numbers were also affected only for the relevant subset. LeakData does not extend either field to all 285,086 people or invent an unknown subgroup size.

Why Is Behavioral Health Information Sensitive?

NTBHA coordinates mental-health and substance-use treatment and services in Dallas, Ellis, Hunt, Kaufman, Navarro, and Rockwall counties. Even a person's connection with these services can carry private context. The sources do not disclose that specific diagnoses or treatment details were involved, so this entry explains the sensitivity without inferring contents.

Personal and health information combined with a Social Security number can increase the risk of identity theft, targeted fraud, and impersonation of a healthcare organization. NTBHA said it had found no evidence of actual or attempted misuse when notices were issued. The absence of known misuse does not mean sensitive-information exposure presents no future risk.

How Is the 285,086-Person Scope Used?

pwnCount and totalRecords use the regulatory total of 285,086 people in the current HHS OCR public row. This is the protected-health-information scope the organization reported to the federal authority. It is not the count of the subset whose Social security numbers were involved and is not applied as a separate total to every data class.

The event represents one NTBHA network access window; the six service counties are not opened as separate breaches. No verified county- or program-level person counts were published, so the total is neither divided nor multiplied by assumption. This avoids possible duplicate counting and the addition of unknown clinical fields.

What Should Affected People Do?

NTBHA offered complimentary credit monitoring and identity-theft protection to people whose Social security numbers were involved. The organization said it reset passwords, expanded multifactor authentication, and deployed advanced endpoint-detection tools. Notice recipients should follow the enrollment instructions and personal scope stated in their letter.

People should inspect credit reports and health-insurance explanations for unfamiliar accounts, services, or claims. Unexpected payment or identity-verification requests made in the name of NTBHA or a mental-health provider should be checked through a known official channel. LeakData does not host stolen files; it documents only verified incident metadata and practical follow-up steps.

285.1 Thousand
Affected Accounts
3
Data Types
High
Severity
Yes
Verification

Exposed Data Types

3
Personal information
Protected health information
Social security numbers

Additional Information

Added DateJuly 27, 2026
Breach DateOctober 13, 2025
Domainntbha.org
SourceConfirmed unauthorized network access; patient files may have been viewed or acquired
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information