Were you recently affected by a data breach?

Oak Hill Data Breach

Oak Hill, a Connecticut nonprofit serving individuals with disabilities, disclosed a data security incident from October 2025. On May 13, 2026, Oak Hill confirmed names, Social Security numbers, driver’s license numbers, and medical information may have been exposed. Notification letters were mailed starting June 30, 2026.

Oak Hill
Date of Breach: October 6, 2025 (confirmed May 13, 2026)
CAU logo

Who was affected:

Clients of Oak Hill

Impacted Data:

Full names, dates of birth, Social Security numbers, driver’s license or state ID numbers, medical information, health insurance information

Oak Hill, formally known as The Connecticut Institute for the Blind, Inc., has notified individuals that a cybersecurity incident on its network may have exposed their personal and health-related information. Oak Hill serves children and adults with intellectual, developmental, physical, and visual disabilities across Connecticut, meaning the individuals affected by this breach may already be among the state’s most vulnerable residents. Organizations that provide care to vulnerable populations carry an especially important responsibility to protect the personal and medical information entrusted to them.

Oak Hill’s Data Breach Investigation

Oak Hill, the operating name of The Connecticut Institute for the Blind, Inc., is a nonprofit organization that serves children and adults with intellectual, developmental, physical, and visual disabilities through a wide range of programs, including residential and group home care, community-based education, employment training, assistive technology services, special education support, recreational programming, early intervention, and advocacy across communities statewide in Connecticut.

According to a notice provided by the organization, Oak Hill experienced a data security incident on or about October 6, 2025. Upon learning of the incident, Oak Hill commenced an investigation, working with outside cybersecurity experts to determine whether unauthorized access or acquisition of files had occurred, and if so, what information was involved. This investigation determined that certain files stored on the Oak Hill network had, in fact, been subject to unauthorized access or acquisition.

The organization then undertook a lengthy review of the affected files to determine whether any personal information had been involved. On May 13, 2026, more than seven months after the incident was first detected, Oak Hill confirmed that certain files containing personal information had indeed been impacted. According to the organization, the types of information potentially exposed included both personally identifiable information and protected health information, specifically full names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information. Oak Hill began mailing notification letters to potentially affected individuals on June 30, 2026, nearly a year after the original incident.

Nonprofit organizations that serve individuals with disabilities, like Oak Hill, often maintain uniquely sensitive combinations of personal, medical, and financial information about the people they serve, since providing services such as residential care, special education, and assistive technology support requires collecting detailed records about a person’s health conditions, guardianship or caregiving arrangements, and government benefits eligibility. This makes such organizations attractive targets for cybercriminals, even though nonprofits frequently operate with more limited cybersecurity budgets and staffing than larger corporate or government entities handling comparable volumes of sensitive data.

The combination of Social Security numbers, dates of birth, and government-issued identification numbers exposed in this incident creates significant identity-theft risk for affected individuals, who may already face additional barriers to monitoring their own financial accounts or recognizing signs of fraud depending on the nature of their disability. When medical and health insurance information is exposed alongside these identifiers, the risk extends to medical identity theft as well, in which a criminal uses a victim’s identity to obtain healthcare services, medical equipment, or prescription medications, potentially corrupting the victim’s own medical records in the process.

The nearly year-long gap between the October 2025 incident and the June 2026 notification letters illustrates how long thorough forensic reviews can take, particularly for organizations without large in-house cybersecurity teams that must rely on external experts to review potentially large volumes of files. Oak Hill has stated that individuals whose Social Security numbers may have been involved are encouraged to enroll in complimentary credit monitoring services referenced in their notification letters, and has established a dedicated response line for individuals with questions about the incident.

When Did This Breach Occur?

Oak Hill has provided a relatively detailed timeline of this incident. The organization states that it experienced a data security incident on or about October 6, 2025. Upon learning of the issue, Oak Hill began an investigation with the assistance of external cybersecurity experts to determine the scope of the unauthorized access.

That investigation determined that certain files were subject to unauthorized access or acquisition, and Oak Hill then conducted a further review specifically to determine whether personal information had been involved in the incident. On May 13, 2026, more than seven months after the incident was first detected, Oak Hill confirmed that files containing personal information had been affected. The organization began mailing notification letters to potentially affected individuals on June 30, 2026, roughly nine months after the original security incident occurred.

What Information Was Breached?

According to Oak Hill’s notice, the types of information potentially exposed in this incident included both personally identifiable information and protected health information. Specifically, the organization has stated that full names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information may have been involved.

Because Oak Hill serves individuals through residential care, education, employment training, and other support programs, the personal records it maintains can include especially sensitive details related to a person’s disability status, care arrangements, and medical history, in addition to standard identifying information. Individuals whose Social Security numbers may have been involved are specifically being encouraged by Oak Hill to enroll in complimentary credit monitoring services referenced in their notification letters. If you received a letter from Oak Hill, review it closely, as it should describe which categories of your information were specifically affected.

What You Can Do

If you or a family member received a notification letter from Oak Hill, consider taking these steps:

  • Enroll in the complimentary credit monitoring services referenced in your notification letter.
  • Review your credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
  • Consider placing a fraud alert or security freeze on your credit files.
  • Watch health insurance statements closely for any services you did not receive.
  • Call Oak Hill’s dedicated response line at 1-877-418-8555 with questions about the incident.

These steps can help you catch any signs of fraud early and limit potential harm from the breach.

File a Data Breach Lawsuit Against Oak Hill

If your personal or medical information was exposed in the Oak Hill data breach, you may have legal options available to you. Organizations that serve vulnerable populations, including children and adults with disabilities, have a heightened responsibility to protect the sensitive personal and health information entrusted to them, and a failure to do so can leave already-vulnerable individuals exposed to serious harm.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's Office on August 14, 2026 (the exact date the incident occurred has not been publicly disclosed)
Date of Breach: Reported to the Vermont Attorney General's Office on August 14, 2026 (the exact date the incident occurred has not been publicly disclosed)
Date of Breach: Reported to the Vermont Attorney General's Office on August 14, 2026 (the exact date the incident occurred has not been publicly disclosed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.