[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc7DBSpELztpzITy_43PWqgrS1uja8E640zESb_f-hRQ":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"severity":32,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66f164bfe05da4623dedae","OperationPAR2025","Operation PAR 2025 Data Breach","operation-par-2025","operationpar.org",{"name":12,"sector":13,"country":14,"website":10},"Operation PAR, Inc.","Healthcare","United States","2025-06-10T00:00:00.000Z","2026-07-27T05:49:24.719Z",145714,[19,20,21,22,23,24,25,26,27,28],"Personal information","Protected health information","Names","Addresses","Dates of birth","Social Security numbers","Driver's license numbers","Financial account information","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The Operation PAR 2025 data breach\u003C\u002Fstrong> was a security incident that began when the Florida behavioral-health and addiction-treatment organization detected unauthorized access to its network on or about June 10, 2025. Its official June 24, 2026 update says the access resulted in the potential exposure of a limited amount of data it maintained.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights lists the Operation PAR event as a Hacking\u002FIT Incident affecting 145,714 people. LeakData imported no person or patient rows, and importedRecordCount is zero. This entry describes only verified incident metadata from the official notice and regulatory report.\u003C\u002Fp>\n\u003Ch2>How Was the Operation PAR Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the Data Security Incident Notification on Operation PAR's own domain and the June 24, 2026 update linked from that page. The update directly states the incident date, unauthorized network access, investigation-completion date, notification start, and categories of information that may have been affected.\u003C\u002Fp>\n\u003Cp>The second confirmation is HHS OCR's breach report. The federal record identifies the entity as a business associate, classifies the event as a hacking\u002FIT incident involving a network server, gives a June 25, 2026 submission date, and reports 145,714 affected individuals. The sources make no verified attacker or ransomware-group attribution, so this entry adds none.\u003C\u002Fp>\n\u003Ch2>What Happened on June 10, 2025?\u003C\u002Fh2>\n\u003Cp>Operation PAR detected unauthorized access to its network on or about June 10 and said that the access resulted in the potential exposure of a limited amount of data it maintained. It secured the network, reported the event to law enforcement, and began a thorough investigation with external cybersecurity professionals experienced in such incidents.\u003C\u002Fp>\n\u003Cp>The official update does not disclose the first and last access times, the intrusion technique, or whether files were conclusively exfiltrated. The breachDate field therefore uses June 10, 2025, the approximate detection date in the source, and does not invent an access duration. There is also no verified evidence in the sources that the information was published or offered for sale.\u003C\u002Fp>\n\u003Ch2>When Were the Review and Notifications Completed?\u003C\u002Fh2>\n\u003Cp>Operation PAR determined on June 10, 2026, roughly one year after discovery, that the affected files may have contained personal information. Beginning June 25, 2026, the organization notified people whose information may have been included in files accessed by the unauthorized party, in accordance with state and federal law.\u003C\u002Fp>\n\u003Cp>The initial website notice said the investigation was ongoing and that affected systems might contain names, addresses, dates of birth, Social Security numbers, and health-insurance information. The later official update additionally confirmed driver's-license, financial-account, and medical-information categories. This entry relies on that later completed update for scope.\u003C\u002Fp>\n\u003Ch2>What Personal Information May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>The fields varied by individual and may include a first and last name, date of birth, Social Security number, driver's-license number, and financial-account information. The initial notice also identified addresses as potentially involved. This combination creates serious exposure to identity theft, fraudulent account opening, account takeover, and targeted phishing.\u003C\u002Fp>\n\u003Cp>The official language does not say every field was present for all 145,714 people and provides no field-level counts. This entry therefore does not assume that every person's Social Security, driver's-license, or financial-account information was involved. Passwords, payment cards, passports, and biometric data are not added because the sources do not confirm them.\u003C\u002Fp>\n\u003Ch2>What Health Information Was Involved?\u003C\u002Fh2>\n\u003Cp>The June 24 update lists medical information and health-insurance information among the possible data categories. Because Operation PAR provides behavioral-health, substance-use-disorder treatment, prevention, and support services, such information may create exposure to medical-identity theft and fraud targeted around sensitive health circumstances.\u003C\u002Fp>\n\u003Cp>The organization's earlier notice expressly said it had no evidence that its cloud-based electronic-health-record system was compromised as a result of the incident. The sources do not list specific diagnosis, treatment, prescription, or medical-record-number fields. LeakData therefore does not go beyond the general medical and insurance categories or infer that complete clinical records were involved.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Recipients should regularly review credit reports, financial-account activity, and health-insurance explanation-of-benefits statements for unfamiliar transactions or services. If an unknown account, transfer, provider, or treatment appears, the relevant organization should be contacted through a verified channel; a fraud alert or free credit freeze may also be appropriate.\u003C\u002Fp>\n\u003Cp>Operation PAR announced a dedicated confidential response line at 866-659-7103. Social Security numbers, financial-account details, or health information should not be shared through unexpected links or calls claiming to represent the organization. LeakData does not host, distribute, or make searchable breach files, patient records, or identity numbers.\u003C\u002Fp>","Official Operation PAR update confirming unauthorized network access and potential data exposure",false,"High","completed","\u002Fuploads\u002Flogo\u002Foperationpar_org.png"]