Key Takeaways
- Operation PAR found that unauthorized network access exposed personal and protected health information belonging to 145,714 current and former clients.
- The compromised files included Social Security numbers, financial account details, medical information, and health insurance data.
- Separate incidents at Eyemart Express, Vanderbilt Health, and Averhealth Holdings show the range of identity, email, and network risks facing healthcare businesses.
Operation PAR, Inc. has notified 145,714 current and former clients that unauthorized access to its computer network exposed personal information and protected health information. The Pinellas Park, Florida-based addiction treatment and mental health service provider began mailing notification letters on June 25, 2026.
Suspicious activity was initially detected on June 10, 2025. Operation PAR took steps to secure its systems and opened an investigation into the nature and scope of the intrusion. On June 10, 2026, one year after detecting the activity, Operation PAR confirmed that affected files contained client information.
The exposed data varied by person. It included first and last names, dates of birth, Social Security numbers, driver's license numbers, financial account information, medical information, and health insurance information. That combination creates several possible avenues for misuse, ranging from conventional identity fraud to highly targeted phishing and social engineering.
Behavioral health records carry risks that extend beyond financial loss. Information connected to addiction treatment or mental health services can be intensely private, creating potential concerns around stigma, coercion, discrimination, and patient trust. Substance use disorder records may also receive additional confidentiality protections under 42 CFR Part 2, alongside requirements established by the HIPAA Privacy Rule and Security Rule.
Operation PAR stated it implemented additional security measures to prevent future incidents. Its notification letters provided guidance on protecting personal information and watching for fraud. Complimentary credit monitoring and identity theft protection do not appear to have been offered, according to the breach account published by HIPAA Journal.
The notification letters did not identify an attacker. However, the incident appears connected to Worldleaks, which added Operation PAR to its dark web leak site in July 2025 and subsequently released allegedly stolen data. Attribution based on a criminal group's claims should be treated cautiously, but public leaking can materially increase the risk because exposed files may circulate long after the original incident.
Treatment businesses attract significant attention from cybercriminals because their systems consolidate identity records, insurance details, clinical histories, payment information, and contact data. The scale is substantial as well. SAMHSA reported that more than 46 million people aged 12 or older met the criteria for a substance use disorder in 2022, making the security of treatment infrastructure a broad healthcare concern rather than a niche compliance issue.
Operation PAR is not alone. Behavioral Health Business reported a breach involving BayMark Health Services in 2025, while Oglethorpe, Inc. has also disclosed an incident affecting behavioral health records. These cases indicate that organizations handling substance use and mental health data face recurring pressure from data theft and extortion operations.
Other healthcare disclosures announced alongside Operation PAR illustrate different attack paths. Eyemart Express said unauthorized access on February 12, 2026, potentially compromised information belonging to an undisclosed number of individuals. The data included names, addresses, dates of birth, Social Security numbers, prescription information, insurance information, and eyeglass purchase details. Eyemart Express offered credit monitoring and identity theft protection to people whose Social Security numbers were involved.
Vanderbilt Health traced its incident to a phishing link that captured an employee's credentials. The compromised email account was accessible from March 23 to March 27, 2026, and contained patient names, diagnoses, procedure information, medical record numbers, provider or facility names, and visit dates. Vanderbilt Health said electronic medical records were not accessed and Social Security numbers and financial information were not involved. The affected population remains undisclosed.
Averhealth Holdings, the parent company of Avertest, reported a breach affecting 9,909 individuals. Unauthorized access occurred between December 19, 2025, and January 21, 2026, potentially exposing clinical, insurance, identification, and treatment information. Notifications were mailed July 2, 2026, with credit monitoring offered to individuals whose Social Security numbers were affected.
These incidents demonstrate the necessity for healthcare organizations to secure email identities, properly segment networks, and audit third-party access. The public breach portal maintained by the HHS Office for Civil Rights also makes clear that healthcare data exposure is persistent. For organizations holding particularly sensitive treatment records, delayed discovery and notification can compound both regulatory exposure and the damage to client confidence.
⬇️