Were you recently affected by a data breach?

Psychiatry & Holistic Health Center Data Breach

Psychiatry & Holistic Health Center, a Norwell, Massachusetts practice, says it discovered unauthorized activity in a staff account on its TherapyNotes records system on October 7, 2026. Patient billing, payment and insurance information was involved.

Psychiatry & Holistic Health Center
Date of Breach: Discovered October 7, 2026
CAU logo

Who was affected:

Clients of Psychiatry & Holistic Health Center

Impacted Data:

Names and information associated with billing, payment, insurance and health care records; payment card transactions. Social Security numbers not identified as involved at this time.

Psychiatry & Holistic Health Center (PHHC), a mental health practice in Norwell, Massachusetts, has sent patients a notice about unauthorized activity in its electronic health record and practice management system. The notice is posted in the state’s list of data breach notification letters for October 2026.

If you are a patient of the practice and received this notice, here is what has been made public so far and what you can do about it.

Psychiatry & Holistic Health Center’s Data Breach Investigation

PHHC is located on Cordwainer Drive in Norwell, Massachusetts, and its letter is addressed to patients. According to the letter, the practice discovered unauthorized activity involving a staff user account within TherapyNotes, the electronic health record and practice management system it uses. TherapyNotes is a widely used platform for behavioral health practices, and the letter describes the activity as tied to one staff account within it rather than to PHHC’s own network.

The letter says PHHC began investigating immediately and reviewed the relevant account and payment-processing records. It says the practice contacted TherapyNotes about the unauthorized account activity, preserved relevant system and payment-processing records, required staff password changes, and strengthened account security, including by turning on two-factor authentication. PHHC also says it is still reviewing the incident and will provide more information if its investigation finds something that materially changes what it has reported.

One detail sets this notice apart from many others. The letter says the review identified unauthorized payment transactions involving the payment card associated with a patient’s account. The posted copy leaves the dollar amount as a blank template field, so this page does not state any amount. The practice recommends that patients contact their card issuer or financial institution right away, tell them the transactions were unauthorized, and follow their instructions for disputing the charges and protecting the account.

The letter also says that, at this time, the investigation has not identified Social Security numbers as information involved. That is a statement about what had been found as of the notice, not a guarantee, and the practice says it will update patients if that changes.

What the notice does not provide is a total. We did not find the number of patients affected in the Massachusetts listing or in a press statement, so this page does not state a count. The letter also does not say who was behind the unauthorized activity, how the staff account was accessed, or how long the activity went on before it was noticed. We do not guess at those facts.

Mental health practices hold some of the most personal records there are. Even when a notice says that clinical details were not the focus, a record that links a person’s name to a behavioral health provider, a billing history and insurance details can be sensitive by itself. Payment card information adds a direct financial risk. We are describing the general landscape only, and the letter does not say that treatment notes were viewed.

Notices tied to a vendor platform can be confusing for patients, because the company named on the letter is not always the one whose system was used. Here, PHHC is the practice that sent the notice, and the letter ties the activity to an account in a third-party records system. It does not say that TherapyNotes itself suffered a wider breach, and this page does not suggest one. If you have questions about which organization holds your records, the practice is the place to ask. Keep your card statements from recent months handy while you review them for anything unfamiliar.

Practice management systems are a common target because one compromised login can open access to many patient records and to stored payment details. Strong, unique passwords and two-factor authentication make that harder, which is why the steps PHHC says it took are the same ones security guidance usually recommends. Whether the practice’s safeguards were adequate before the incident is not something the letter addresses.

If you received a letter, read it closely and keep a copy. It is the best source for what applies to you. If you think you may be affected but did not receive anything, you can contact the practice’s privacy and security officer, whose contact details appear in the letter, to ask whether your information was involved.

When Did This Breach Occur?

The letter is dated October 7, 2026 and states that PHHC discovered the unauthorized activity on October 7, 2026.

The letter does not say when the unauthorized activity began or ended. A discovery date marks when the practice noticed the problem, and the activity itself may have started earlier.

What Information Was Breached?

The letter says the information may have included the patient’s name and information associated with billing, payment, insurance and health care records.

It also says unauthorized payment transactions involved the payment card associated with the patient’s account. At this time, the investigation has not identified Social Security numbers as involved. The letter says the information is tied to each patient’s own record, so what applies to you is best confirmed in your own notice.

What You Can Do

If you received a notice from Psychiatry & Holistic Health Center or believe you may be affected, consider these steps:

  • Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Watch your financial accounts, tax records and any insurance or medical statements for activity you do not recognize.
  • Be skeptical of unexpected calls, texts or emails that mention the organization, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Psychiatry & Holistic Health Center

If your personal or payment information may have been exposed in this incident, you may have legal options. Healthcare providers are expected to safeguard patient information, and a class action can help hold a provider accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: March 28, 2026 to April 12, 2026
Date of Breach: Discovered October 7, 2026
Date of Breach: Not publicly disclosed (discovered September 9, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.