Kid CenterEd, a Concord, Massachusetts pediatric neuropsychology and educational advocacy practice, has notified clients and their families that a former employee downloaded internal files containing protected health and personal information without authorization before departing the organization. Businesses and practices that hold sensitive medical, psychological, and educational records about children have a responsibility to safeguard that information, including from insiders who no longer have a legitimate need to access it.
Kid CenterEd’s Data Breach Investigation
According to a notice filed with the Massachusetts Attorney General’s office, Kid CenterEd discovered on July 24, 2026 that a former employee who had provided educational advocacy services at the practice downloaded files from its systems in connection with her departure. The download reportedly occurred on or around June 18-19, 2025, more than a year before Kid CenterEd says it uncovered the incident. Kid CenterEd states that the download was not authorized and fell outside the scope of the former employee’s job duties.
Upon discovering the unauthorized download, Kid CenterEd says it engaged outside legal counsel experienced in data privacy and security matters, retained a digital forensic expert to analyze the scope of the access, and suspended the former employee’s account credentials to prevent any further access to its systems. The practice also says it is pursuing legal action against the former employee for an alleged breach of contractual confidentiality obligations, and that it has been communicating with regulators as necessary. Kid CenterEd has not publicly disclosed how many individuals were affected nationwide or in Massachusetts specifically.
Delays between when a data security incident occurs and when it is discovered and disclosed are common, particularly in incidents involving a former insider rather than an external hacking group. Unlike a ransomware attack or a network intrusion, an insider download can go unnoticed for months because the files are simply copied rather than encrypted in a way that triggers automated security alerts. That gap matters to affected families: the longer sensitive records sit outside an organization’s control, the longer the window in which that information could be shared or misused before anyone is notified and able to take protective steps.
The types of records reportedly involved in this incident are especially sensitive because they go well beyond typical financial identifiers. Neuropsychological evaluations, Individualized Education Program (IEP) documents, and clinical assessments contain detailed information about a child’s cognitive functioning, diagnoses, disabilities, and behavioral history. Unlike a Social Security number, this kind of information cannot simply be replaced or frozen, and its disclosure can carry lasting consequences for how a child or family is perceived by schools, insurers, or future service providers. Practices like Kid CenterEd that specialize in educational advocacy and neuropsychological assessment sit at the intersection of healthcare and education record-keeping, which can mean sensitive files are subject to overlapping privacy frameworks and, when compromised, correspondingly broad exposure.
Kid CenterEd’s notice states that affected records did not include Social Security numbers, driver’s license numbers, other government-issued identification numbers, or bank account numbers. That distinction is meaningful for assessing certain kinds of identity-theft risk, but it does not eliminate exposure. The reported records include home addresses and family correspondence, and, for some individuals, credit card authorization forms, all of which can still be leveraged for targeted scams, phishing attempts referencing real details about a child’s evaluation or treatment, or other forms of fraud that do not depend on a Social Security number at all. Families who provided a credit card authorization form to Kid CenterEd may face a narrower but still real risk of unauthorized charges if that specific document was among the files accessed.
Data breach notification laws in Massachusetts and other states require organizations that experience a security incident involving personal information to notify affected residents and, in many cases, state regulators within a defined window after discovery. Kid CenterEd’s notice, dated September 22, 2026, reflects that process. As is common with these filings, the notice describes an ongoing review, meaning the full scope of who was affected and what specific records were involved for each individual may not be finalized at the time letters are sent out.
When Did This Breach Occur?
Kid CenterEd states that the unauthorized download of files took place on or about June 18-19, 2025, when a former employee accessed and downloaded files from the practice’s systems in connection with her departure. Kid CenterEd says it did not discover the incident until more than a year later, on July 24, 2026, after which it began investigating the scope of the download and reviewing which individuals and records were affected. The company’s notification letters to affected clients are dated September 22, 2026.
What Information Was Breached?
Kid CenterEd’s notice states that the files accessed may have included patient and parent/guardian names, home addresses, Individualized Education Programs (IEPs) and related educational and disability records, private evaluations such as neuropsychological and occupational therapy assessments (including test scores and diagnoses), patient histories, family correspondence, observation records, sensory profiles, school evaluations, and medical reports. For some individuals, credit card authorization forms were also reportedly involved. Kid CenterEd states that the affected records did not include Social Security numbers, driver’s license numbers, other government-issued identification numbers, or bank account numbers.
What You Can Do
If you or your child received a notice from Kid CenterEd, consider taking the following steps:
- Remain alert for unexpected correspondence about accounts or services in your name or your child’s name
- Report any suspected identity theft or fraud to your local law enforcement agency
- Monitor your credit card and financial account statements closely, particularly if you previously provided a credit card authorization form to Kid CenterEd
- Review Explanation of Benefits (EOB) statements from your health plan for services you did not receive
- Consider placing a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion
File a Data Breach Lawsuit Against Kid CenterEd
If your or your child’s personal or health information was compromised in the Kid CenterEd data breach, you may have legal options. Organizations that handle sensitive medical, psychological, and educational records are expected to take reasonable steps to protect that information, including limiting what former employees can access or remove upon departure.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.