In late September 2025, Richmond Behavioral Health Authority (RBHA), a Virginia-based behavioral health provider, experienced a ransomware attack. This incident led to the theft of personal information from over 113,000 individuals. The breach was reported to the HHS Office for Civil Rights (OCR) in November 2025 under the HIPAA Breach Notification Rule.
The confirmed data types exposed in this breach include names, Social Security numbers, financial information, and health information (Protected Health Information or PHI). The incident affected approximately 113,232 individuals. While medical data is confirmed due to the nature of the organization, the specific elements of financial and SSN exposure were also reported by SecurityWeek. The full extent of specific data elements compromised in every instance remains unclear.
More details may emerge as investigations continue, and official notices to affected individuals may be ongoing.