Park Place Behavioral Healthcare Data Breach Exposes PHI and PII

Published
September 25, 2026
Updated
September 25, 2026
Park Place Behavioral Healthcare Data Breach Exposes PHI and PII
Park Place Behavioral Healthcare

Osceola Mental Health Inc., doing business as Park Place Behavioral Healthcare, has disclosed a data breach involving unauthorized access to its computer systems.

The company is a nonprofit community behavioral health provider based in Kissimmee, Florida, that provides a range of mental health and substance use treatment services for adults and children, including crisis stabilization, outpatient therapy, inpatient care, residential treatment and medication management.

The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation. The company posted a notice on its website.

On July 23, 2026, Osceola Mental Health became aware of unusual activity on its computer systems. Upon discovery, the company secured its environment and engaged a specialized third-party cybersecurity firm to conduct a comprehensive investigation into the nature and scope of the incident.

The forensic investigation was completed on Aug. 19, 2026. It determined that certain information stored on the company's systems was copied by an unauthorized party.

Following the investigation, the company conducted a thorough review of the impacted files to determine which specific individuals were affected and what types of data were involved in the breach.

The types of personally identifiable information (PII) that may have been exposed include names, Social Security numbers, dates of birth, driver's license numbers, other government-issued ID numbers and financial account information.

Protected health information (PHI) may also have been exposed, including health information and health insurance information.

Osceola Mental Health's response to the breach

Osceola Mental Health is offering affected individuals complimentary credit monitoring and identity theft restoration services through IDX, a data breach and recovery services provider.

Affected individuals must enroll within 90 days of the date of their notification letter to receive these services.

Individuals with questions about the incident or who need help enrolling in credit monitoring can call a dedicated support line during the hours of 9 a.m. to 9 p.m. Eastern Time, Monday through Friday, excluding U.S. national holidays.

The company can also be reached at its main office at 200 Park Place Blvd., Kissimmee, FL 34741, or by calling 407-846-0023.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
July 23, 2020
Total People Affected
Information Types Exposed
  • Social Security number
  • Date of birth
  • Driver's/license number
  • Other government issued ID number
  • Financial account information
  • Government-issued ID number
  • Health information
  • Health insurance information
  • Name
  • Medical Records
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image