Were you recently affected by a data breach?

Kern Psychiatric Health and Wellness Center Data Breach

Kern Psychiatric Health and Wellness Center, Inc. discovered in June 2026 that files on its management company’s network were accessed without authorization, potentially exposing patients’ Social Security numbers, medical records, and other sensitive health information.

Kern Psychiatric Health and Wellness Center
Date of Breach: June 22, 2026 (discovered)
CAU logo

Who was affected:

Clients of Kern Psychiatric Health and Wellness Center

Impacted Data:

Names, Social Security numbers, driver’s license or government-issued ID numbers, dates of birth, diagnosis and treatment information, prescription information, provider names and locations, dates of service, medical record numbers, patient account numbers, and Medicare or Medicaid ID numbers

Kern Psychiatric Health and Wellness Center, Inc. has notified patients that sensitive personal and medical information may have been exposed after an unauthorized party accessed files on the computer network of Genesis Healthcare Management, the company that manages Kern Psychiatric’s operations. The information reportedly involved includes Social Security numbers, government-issued identification numbers, and detailed medical treatment records.

Healthcare providers and the companies that manage their day-to-day operations are entrusted with some of the most sensitive information a person can share, from diagnoses to Social Security numbers, and they carry a legal and ethical responsibility to keep that information secure.

Kern Psychiatric Health and Wellness Center’s Data Breach Investigation

According to a notification letter sent to affected individuals, Genesis Healthcare Management discovered unusual activity on its computer network on June 22, 2026. Genesis, which manages Kern Psychiatric Health and Wellness Center’s operations and houses certain PWC patient data on its systems, immediately began an investigation with the assistance of third-party cybersecurity specialists. That investigation determined that certain files on the network, which contained information belonging to Kern Psychiatric patients, had been accessed by an unauthorized party without permission.

Following the discovery, Kern Psychiatric and Genesis undertook a comprehensive review of the affected files to determine exactly what information was contained in them and which individuals were impacted. That review has since concluded, and notification letters describing the incident began going out to affected patients starting August 19, 2026.

Breaches involving behavioral health and psychiatric providers carry particular risks beyond the usual exposure of financial identifiers. When diagnosis, treatment, and prescription information is compromised alongside Social Security numbers and government-issued identification, patients face not only the standard threats of identity theft and financial fraud, but also the possibility that sensitive mental health details could be exposed, misused, or used to target them with tailored phishing or extortion schemes. Healthcare organizations and their vendors remain frequent targets for cybercriminals precisely because medical records combine financial identifiers with deeply personal health data, making a single successful intrusion extremely valuable on illicit markets.

The combination of data types reportedly involved here, Social Security numbers, driver’s license or government-issued ID numbers, dates of birth, and specific medical record and treatment details, is exactly the kind of information that enables sophisticated identity theft, medical insurance fraud, and fraudulent use of a victim’s identity to obtain prescriptions or medical services in their name. Patients whose information was exposed should treat any unexpected medical bills, insurance statements, or new account notices with heightened suspicion in the months following this notification.

Kern Psychiatric has stated it has no reason to believe the information has been or will be misused, and that Genesis has taken steps to help ensure the data was re-secured following the intrusion. Genesis also reported the incident to law enforcement and says it is reviewing its internal data protection policies and procedures as a result.

When Did This Breach Occur?

Genesis Healthcare Management, which manages Kern Psychiatric Health and Wellness Center’s operations, discovered unusual activity on its network on June 22, 2026. Following an investigation with third-party specialists, a comprehensive review of the affected files concluded, and Kern Psychiatric began sending written notification to affected individuals on August 19, 2026.

What Information Was Breached?

The notification letter states that the potentially impacted information includes each patient’s name in combination with one or more of the following, where previously provided: Social Security number, driver’s license number or other government-issued identification number, date of birth, diagnosis and treatment information, prescription information, provider name and location, dates of service, medical record number, patient account number, and Medicare or Medicaid identification number.

What You Can Do

Kern Psychiatric Health and Wellness Center is offering affected individuals complimentary credit monitoring and identity protection services through TransUnion. Those who received a notification letter can enroll using the unique code provided in that letter. In addition to enrolling in the offered monitoring service, affected individuals should consider taking the following steps:

  • Enroll in the complimentary credit monitoring service before the enrollment deadline stated in your letter.
  • Request a free copy of your credit report from each of the three major credit bureaus and review it for unfamiliar accounts or inquiries.
  • Consider placing a fraud alert or a security freeze on your credit file with Equifax, Experian, and TransUnion.
  • Closely monitor medical bills, insurance statements, and explanation-of-benefits forms for services you did not receive.
  • Report any signs of identity theft or fraud to local law enforcement and the Federal Trade Commission.

File a Data Breach Lawsuit Against Kern Psychiatric Health and Wellness Center

If you received a data breach notification letter from Kern Psychiatric Health and Wellness Center, Inc., you may have legal options available to help recover damages related to the exposure of your personal and medical information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: December 18, 2025 (discovered by vendor Aesto, LLC)
Date of Breach: June 22, 2026 (discovered)
Date of Breach: Reported to the Vermont Attorney General's Office on August 21, 2026; underlying breach and discovery dates not yet publicly disclosed.
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.