Provident Behavioral Health Data Breach Exposes PHI and PII

Published
September 8, 2026
Updated
September 8, 2026
Provident Behavioral Health Data Breach Exposes PHI and PII
Provident Behavioral Health
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Provident Behavioral Health, a St. Louis-based nonprofit mental health care provider, disclosed a data breach that may have resulted in unauthorized access to individuals' personal and medical information.

The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation. The company also posted a notice on its website and began notifying affected individuals by mail on June 4, 2026.

Provident Behavioral Health detected suspicious activity on its computer systems on April 3, 2026. Upon discovering the activity, the company isolated the impacted systems and engaged a specialized third-party cybersecurity firm. The firm assisted with remediating the affected systems and conducted a comprehensive forensic investigation to determine the nature and scope of the incident.

The forensic investigation found evidence that data stored on the impacted systems was acquired by an unauthorized user. Following this finding, the company diligently reviewed the potentially impacted files to identify and catalog the types of information present within them and to determine which individuals' information may have been affected.

The types of personally identifiable information (PII) that may have been exposed included names, addresses, dates of birth, Social Security numbers, driver's license or state identification numbers, email addresses, phone numbers and financial account information.

The breach also involved protected health information (PHI), including medical information, medical records and health insurance information.

Provident Behavioral Health's response to the breach

Provident Behavioral Health is providing affected individuals with complimentary credit monitoring and identity theft restoration services.

The company encourages individuals to remain vigilant against incidents of identity theft and fraud. It recommends that affected individuals review their account statements regularly and monitor their credit reports for any suspicious or unauthorized activity.

The company also advises individuals to contact their financial institutions and all major credit bureaus to inform them of the breach and to take whatever steps are recommended to protect their accounts. Its notification included detailed guidance on how to place fraud alerts and credit freezes, how to obtain free credit reports and how to contact the Federal Trade Commission for further assistance.

Individuals with questions or concerns about the breach can call 844-209-5987 (toll free) Monday through Friday from 9 a.m. to 9 p.m. Eastern time, excluding U.S. national holidays.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • names
  • email addresses
  • social security numbers
  • addresses
  • phone numbers
  • dates of birth
  • driver's license numbers
  • medical information
  • financial account information
  • medical records
  • drivers licenses
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image