All Breaches
June 6, 2025 Verified Sensitive Record Healthcare

Oglethorpe, Inc. 2025 Data Breach

The Oglethorpe, Inc. 2025 data breach was a cybersecurity incident in which an unauthorized party accessed systems belonging to a network of mental-health and addiction-treatment facilities, detected on June 6, 2025. Oglethorpe's signed notice confirms that the actor acquired certain personal information that could include names, dates of birth, driver's-license numbers, Social security numbers, and medical information.

The public breach record maintained by the U.S. Department of Health and Human Services Office for Civil Rights classifies Oglethorpe, Inc. as a Healthcare Provider and the event as a Hacking/IT Incident involving a Network Server. The federal record reports 92,332 affected people. LeakData holds no individual rows from this population; importedRecordCount is zero and this entry contains verified incident metadata only.

How Was the Oglethorpe 2025 Breach Confirmed?

The primary source is the four-page Notice of Data Security Incident sent on Oglethorpe's behalf on October 31, 2025. The letter directly explains discovery, the forensic investigation, completion dates for the review, the types of information acquired, security measures taken, and services offered to affected people.

The second source is the HHS OCR breach portal, which confirms the count, organization type, incident category, and information location. The third is HIPAA Journal's November 4, 2025 report, which independently describes the access window, file review, and notification scope. The company identity, timeline, data categories, and 92,332-person total align across the sources.

What Happened on June 6, 2025?

On or about June 6, Oglethorpe detected a security incident in which an unauthorized third party accessed its network environment. The organization engaged outside forensic specialists to secure the environment and investigate the extent of unauthorized activity. The review described by HIPAA Journal places the access window between May 15 and June 6, 2025.

The investigation concluded on September 16 and determined that the unauthorized party acquired information belonging to certain individuals during the event. Oglethorpe then reviewed the affected files to identify people and addresses, completing that work on October 23. The breachDate field uses the June 6 detection date disclosed in the organization's notice, not an estimated start date.

What Information Was Affected?

According to the notice, the potentially accessed and acquired fields were first and last names, dates of birth, driver's-license numbers, Social security numbers, and medical information. This combination is highly sensitive because it can support identity theft, fraudulent account creation, targeted scams, and misuse of a medical identity.

The organization did not say that every field appeared for all 92,332 people. The entry therefore creates no subgroup counts and does not add undisclosed addresses, email addresses, passwords, payment cards, bank accounts, or health-insurance identifiers. The sources also do not establish that the event was ransomware or that the stolen files were publicly released.

What Does the 92,332-Person Scope Mean?

The pwnCount and totalRecords fields use the 92,332 affected-person count in the public HHS OCR row. The same total appears in public reporting based on the Maine Attorney General filing. It is a count of people within the notification population, not a count of files, medical records, facility visits, or individual data elements.

Oglethorpe is a network providing management solutions to centers, clinics, and hospitals specializing in mental health, substance-use treatment, and behavioral-health services. Because the precise division of affected current and former patients and employees was not publicly disclosed, this entry does not present those groups as separate totals.

What Measures Did Oglethorpe Take?

After detecting the event, the organization said it worked with outside specialists to secure the network, wiped and rebuilt affected systems, and reviewed or changed policies, procedures, and software relating to system and server security. Oglethorpe also notified the FBI and said it was fully cooperating with the investigation.

The October 31 letter says no evidence of specific misuse had been found by that date. Even so, affected individuals received twelve months of single-bureau credit monitoring, a credit report and score service, and fraud assistance at no charge. The absence of known misuse at notification does not remove the possibility of later identity or healthcare fraud.

What Should Affected People Do?

Notice recipients should activate the complimentary monitoring service within the letter's enrollment period and regularly review credit reports, new-account inquiries, and healthcare service histories. An unfamiliar credit account, medical procedure, or insurance claim should be reported through a previously known official channel for the relevant institution.

The combination of Social security numbers and medical information can make targeted phishing convincing. Links in unexpected messages claiming to be from Oglethorpe, a treatment facility, credit bureau, or insurer should not be opened directly; contact should begin through an official site or verified number. LeakData does not distribute or provide search access to stolen personal information.

92.3 Thousand
Affected Accounts
7
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

7
Personal information
Protected health information
Names
Dates of birth
Driver's license numbers
Social security numbers
Medical information

Additional Information

Added DateJuly 27, 2026
Breach DateJune 6, 2025
Domainoglethorpeinc.com
SourceOfficial Oglethorpe notice confirming unauthorized acquisition of personal information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information