[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOttiN5yAqugXeVQQer_Dcbe1ncPp3qYEf3pAkhX1R8M":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":24,"source":25,"isVerified":4,"isSpamList":26,"isSensitive":4,"processingStatus":27,"logoUrl":28,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":29},"6a675bdd75e06ffcf362f5bd","RichmondBehavioralHealthAuthority2025","Richmond Behavioral Health Authority 2025 Data Breach","richmond-behavioral-health-authority-2025","rbha.org",{"name":12,"sector":13,"country":14,"website":10},"Richmond Behavioral Health Authority","Healthcare","United States","2025-09-29T00:00:00.000Z","2026-07-27T13:23:41.323Z",113232,[19,20,21,22,23],"Names","Social Security numbers","Passport numbers","Financial account information","Health information","\u003Cp>\u003Cstrong>The Richmond Behavioral Health Authority 2025 data breach\u003C\u002Fstrong> involved malicious actors accessing the Virginia behavioral-health organization's network around September 29, 2025 and using ransomware to encrypt portions of its systems. RBHA detected the incident September 30 and said the access was terminated as soon as it was discovered. Its notice says personal or protected health information may have been seen or accessed.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists 113,232 affected individuals for Richmond Behavioral Health Authority and classifies the event as a network-server “Hacking\u002FIT Incident.” This number is stored in pwnCount and totalRecords as the official person total. importedRecordCount is zero because no raw person-level data was obtained.\u003C\u002Fp>\n\u003Ch2>How Was the RBHA Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is RBHA's data-security notice dated December 4, 2025 and published on its own domain. The document directly describes the September 29 access, September 30 discovery, ransomware encryption of portions of the network, possible data fields, the organization's response, and its 844-572-2716 assistance line.\u003C\u002Fp>\n\u003Cp>The second primary source is the HHS\u002FOCR row dated November 28 that reports 113,232 affected people. ClaimDepot's incident page provides an independent cross-check tying the same chronology, HHS total, and organization notice together. This record uses secondary details only where consistent with the official document and does not add an attacker name or an unproven data-exfiltration claim.\u003C\u002Fp>\n\u003Ch2>What Happened on September 29–30, 2025?\u003C\u002Fh2>\n\u003Cp>According to RBHA's investigation, malicious actors accessed the network around September 29 and deployed ransomware to encrypt portions of it. The organization became aware of the data incident around September 30. Management, information-technology staff, and third-party cybersecurity experts were engaged to investigate, secure information, and protect the network from further compromise.\u003C\u002Fp>\n\u003Cp>The official letter says the actors' network access was terminated as soon as it was detected. It also specifically states there was no definitive evidence that personal information had been accessed and that RBHA had received no indication of unauthorized misuse as of publication. The network and ransomware incident is verified, but it should not be assumed that every data field was copied or used.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>The official notice says a full name, or first initial and last name, may have been seen or accessed together with a Social Security number, passport number, financial-account information, or health information. Scope varies by individual. It cannot be concluded that every field was present for every person, that actors opened every field, or that the information was published online.\u003C\u002Fp>\n\u003Cp>The notice does not break health information into narrower diagnosis, treatment, medication, or insurance fields, so LeakData does not add those details without evidence. It also does not specify the type of financial account. Data classes are limited to the organization's own language; the general profile of a healthcare institution is not evidence that undisclosed data types were involved.\u003C\u002Fp>\n\u003Ch2>How Should the 113,232 Figure Be Read?\u003C\u002Fh2>\n\u003Cp>113,232 is the affected-person count published for this incident in the HHS\u002FOCR portal. It is not a file count, an attacker-claimed row volume, or the number of accounts loaded into LeakData. pwnCount and totalRecords show the official person total, while importedRecordCount 0 means that no raw, searchable person-level records were imported; it does not mean that nobody was affected.\u003C\u002Fp>\n\u003Cp>The November 28 date in the HHS row is the federal portal report date, not the day the incident began. The official letter places access around September 29 and discovery around September 30. December 4 is the letter date. Keeping these dates distinct helps readers separate the incident timeline from the regulatory and consumer-notification stages.\u003C\u002Fp>\n\u003Ch2>What Are the Identity, Financial, and Health Risks?\u003C\u002Fh2>\n\u003Cp>A name combined with a Social Security or passport number can increase the risk of impersonation, fraudulent accounts, and convincing phishing. Financial-account information may be used in false payment or account-verification messages, while health information can support personalized scams and privacy harms. The absence of confirmed misuse in the notice does not eliminate risk, but it should not be turned into a claim that misuse occurred.\u003C\u002Fp>\n\u003Cp>Recipients should regularly review bank and card activity, credit reports, and relevant healthcare accounts or statements. An unexpected email, message, or call claiming to represent RBHA should not receive a full SSN, passport details, password, payment information, or one-time code. Users should contact the organization through its verified website or the channel in their letter instead of using details supplied in an unsolicited message.\u003C\u002Fp>\n\u003Ch2>What Did RBHA Do and What Can Recipients Do?\u003C\u002Fh2>\n\u003Cp>RBHA said it began a scope investigation with technology experts, implemented additional safeguards, reviewed its system architecture, and strengthened policies intended to prevent future attacks. The organization also encouraged people to monitor account statements and credit reports and remain alert for signs of identity theft and fraud.\u003C\u002Fp>\n\u003Cp>Questions can be directed to 844-572-2716 on weekdays from 8:00 a.m. to 5:30 p.m. Central Time. A recipient should treat their individual letter as the primary source for the data types associated with them and contact the relevant financial or healthcare institution directly if suspicious activity appears. A fraud alert or free credit freeze may also be considered when appropriate.\u003C\u002Fp>","RBHA official notice, HHS\u002FOCR report, and independent incident reporting",false,"completed","\u002Fuploads\u002Flogo\u002Frbha_org.png","High"]