Were you recently affected by a data breach?

The Devereux Foundation Data Breach

The Devereux Foundation, a national behavioral healthcare nonprofit, disclosed that hackers accessed its network in November 2025 and copied files containing Social Security numbers, medical records, and other sensitive personal information.

The Devereux Foundation
Date of Breach: November 6-9, 2025
CAU logo

Who was affected:

Clients of The Devereux Foundation

Impacted Data:

Names, dates of birth, Social Security numbers, driver’s license or state ID numbers, alien registration numbers, taxpayer identification numbers, digital signatures, financial account information, payment card information, medical information, and health insurance information

The Devereux Foundation, a national nonprofit behavioral healthcare organization based in Villanova, Pennsylvania, has notified individuals that their personal information was exposed in a cybersecurity incident affecting its computer network. Nonprofit healthcare organizations that maintain sensitive client, employee, and donor records have a responsibility to keep that information secure from unauthorized access.

The Devereux Foundation’s Data Breach Investigation

According to Devereux’s notice, the organization identified suspicious activity within certain systems on its computer network on November 9, 2025. Devereux states that it took prompt action to isolate the affected systems, assess the security of its network, and launch an investigation with the help of third-party cybersecurity specialists. That investigation determined that an unauthorized actor gained access to certain systems and copied files between November 6 and November 9, 2025.

Devereux’s notice indicates the organization then conducted a thorough review of the affected files to determine what information was contained in them and to whom it related, a process the organization says was recently completed before notification letters began going out on January 8, 2026. This roughly two-month gap between the initial intrusion and public notification is a common pattern in breaches involving large or complex data sets, where investigators must manually confirm which specific records and individuals were affected before consumer notices can legally be sent.

Behavioral health and social services organizations are an increasingly frequent target for cybercriminals because they typically maintain highly sensitive records spanning medical history, insurance information, and government-issued identification numbers for clients, employees, donors, and business partners alike. This combination of data is particularly valuable on the black market since it can support both financial fraud and medical identity theft, in which a stolen identity is used to obtain healthcare services or prescriptions in someone else’s name.

Devereux has stated it has no indication that the exposed information has been used for any fraudulent purpose so far. Nonetheless, as a precaution, the organization is offering complimentary credit monitoring services through Experian to individuals whose information was affected, and reported the incident to law enforcement. Vermont’s Attorney General was notified that at least 43 Vermont residents were among those affected.

When Did This Breach Occur?

Devereux states the unauthorized access to its network occurred between November 6 and November 9, 2025. The organization began notifying affected individuals and relevant regulators on January 8, 2026.

What Information Was Breached?

The categories of information involved varied by individual, but according to Devereux’s notice could include some combination of name, date of birth, Social Security number, driver’s license or state identification number, U.S. alien registration number, taxpayer identification number, digital or electronic signature, financial account information, payment card information, medical information, and health insurance information.

What You Can Do

If you received a data breach notification letter from The Devereux Foundation, consider taking the following steps to protect yourself:

  • Enroll in the complimentary Experian credit monitoring offered in the notification letter
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
  • Review your account statements and explanation of benefits notices for unfamiliar activity
  • Request your free annual credit reports and check them for suspicious accounts
  • Report any suspicious activity to your financial institution or health insurance carrier

File a Data Breach Lawsuit Against The Devereux Foundation

If you received a notice from The Devereux Foundation informing you that your personal information was exposed, you may be entitled to compensation. Organizations that collect and store sensitive personal and medical information have a legal duty to protect it, and when that duty is breached, affected individuals may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: The exact incident date has not been publicly disclosed by the company.
Date of Breach: The exact incident date has not been publicly disclosed by the company.
Date of Breach: January 16-19, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.