Oak Hill, formally known as The Connecticut Institute for the Blind, Inc., has notified individuals that a cybersecurity incident on its network may have exposed their personal and health-related information. Oak Hill serves children and adults with intellectual, developmental, physical, and visual disabilities across Connecticut, meaning the individuals affected by this breach may already be among the state’s most vulnerable residents. Organizations that provide care to vulnerable populations carry an especially important responsibility to protect the personal and medical information entrusted to them.
Oak Hill’s Data Breach Investigation
Oak Hill, the operating name of The Connecticut Institute for the Blind, Inc., is a nonprofit organization that serves children and adults with intellectual, developmental, physical, and visual disabilities through a wide range of programs, including residential and group home care, community-based education, employment training, assistive technology services, special education support, recreational programming, early intervention, and advocacy across communities statewide in Connecticut.
According to a notice provided by the organization, Oak Hill experienced a data security incident on or about October 6, 2025. Upon learning of the incident, Oak Hill commenced an investigation, working with outside cybersecurity experts to determine whether unauthorized access or acquisition of files had occurred, and if so, what information was involved. This investigation determined that certain files stored on the Oak Hill network had, in fact, been subject to unauthorized access or acquisition.
The organization then undertook a lengthy review of the affected files to determine whether any personal information had been involved. On May 13, 2026, more than seven months after the incident was first detected, Oak Hill confirmed that certain files containing personal information had indeed been impacted. According to the organization, the types of information potentially exposed included both personally identifiable information and protected health information, specifically full names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information. Oak Hill began mailing notification letters to potentially affected individuals on June 30, 2026, nearly a year after the original incident.
Nonprofit organizations that serve individuals with disabilities, like Oak Hill, often maintain uniquely sensitive combinations of personal, medical, and financial information about the people they serve, since providing services such as residential care, special education, and assistive technology support requires collecting detailed records about a person’s health conditions, guardianship or caregiving arrangements, and government benefits eligibility. This makes such organizations attractive targets for cybercriminals, even though nonprofits frequently operate with more limited cybersecurity budgets and staffing than larger corporate or government entities handling comparable volumes of sensitive data.
The combination of Social Security numbers, dates of birth, and government-issued identification numbers exposed in this incident creates significant identity-theft risk for affected individuals, who may already face additional barriers to monitoring their own financial accounts or recognizing signs of fraud depending on the nature of their disability. When medical and health insurance information is exposed alongside these identifiers, the risk extends to medical identity theft as well, in which a criminal uses a victim’s identity to obtain healthcare services, medical equipment, or prescription medications, potentially corrupting the victim’s own medical records in the process.
The nearly year-long gap between the October 2025 incident and the June 2026 notification letters illustrates how long thorough forensic reviews can take, particularly for organizations without large in-house cybersecurity teams that must rely on external experts to review potentially large volumes of files. Oak Hill has stated that individuals whose Social Security numbers may have been involved are encouraged to enroll in complimentary credit monitoring services referenced in their notification letters, and has established a dedicated response line for individuals with questions about the incident.
When Did This Breach Occur?
Oak Hill has provided a relatively detailed timeline of this incident. The organization states that it experienced a data security incident on or about October 6, 2025. Upon learning of the issue, Oak Hill began an investigation with the assistance of external cybersecurity experts to determine the scope of the unauthorized access.
That investigation determined that certain files were subject to unauthorized access or acquisition, and Oak Hill then conducted a further review specifically to determine whether personal information had been involved in the incident. On May 13, 2026, more than seven months after the incident was first detected, Oak Hill confirmed that files containing personal information had been affected. The organization began mailing notification letters to potentially affected individuals on June 30, 2026, roughly nine months after the original security incident occurred.
What Information Was Breached?
According to Oak Hill’s notice, the types of information potentially exposed in this incident included both personally identifiable information and protected health information. Specifically, the organization has stated that full names, dates of birth, Social Security numbers, driver’s license or state identification numbers, medical information, and health insurance information may have been involved.
Because Oak Hill serves individuals through residential care, education, employment training, and other support programs, the personal records it maintains can include especially sensitive details related to a person’s disability status, care arrangements, and medical history, in addition to standard identifying information. Individuals whose Social Security numbers may have been involved are specifically being encouraged by Oak Hill to enroll in complimentary credit monitoring services referenced in their notification letters. If you received a letter from Oak Hill, review it closely, as it should describe which categories of your information were specifically affected.
What You Can Do
If you or a family member received a notification letter from Oak Hill, consider taking these steps:
- Enroll in the complimentary credit monitoring services referenced in your notification letter.
- Review your credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
- Consider placing a fraud alert or security freeze on your credit files.
- Watch health insurance statements closely for any services you did not receive.
- Call Oak Hill’s dedicated response line at 1-877-418-8555 with questions about the incident.
These steps can help you catch any signs of fraud early and limit potential harm from the breach.
File a Data Breach Lawsuit Against Oak Hill
If your personal or medical information was exposed in the Oak Hill data breach, you may have legal options available to you. Organizations that serve vulnerable populations, including children and adults with disabilities, have a heightened responsibility to protect the sensitive personal and health information entrusted to them, and a failure to do so can leave already-vulnerable individuals exposed to serious harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.