Behavioral Health Partners of Metrowest
Disclosed May 11, 20224 years ago11,288 affectedConfirmed
The covered entity (CE), Behavioral Health Partners of Metrowest, reported that its business associate (BA) was the victim of cyber-attack affecting the protected health information (PHI) of 10,920 individuals. The PHI involved included names, addresses. Social Security and drivers’ license numbers, and claims information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE strengthened its administrative, technical, and security safeguards to better protect its PHI.
What is known
| People affected | 11,288 (as reported by the organization) |
|---|---|
| Disclosed | May 11, 2022 |
| Happened | Sep 14, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2022 data breach report: Behavioral Health Partners of Metrowestin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Behavioral Health Partners of Metrowest (Business Associate, MA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | May 11, 2022 | 2 |
| HHS archivetotal | May 12, 2022 | 10,920 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Behavioral Health Partners of Metrowest, reported that its business associate (BA) was the victim of cyber-attack affecting the protected health information (PHI) of 10,920 individuals. The PHI involved included nam · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.