Skip to content

Valley Mountain Regional Center

Disclosed Jul 25, 20251 year ago529 affectedConfirmed

Official notice

Valley Mountain Regional Center, the business associate (BA), reported that an employee posted the protected health information (PHI) of 529 individuals on its website. The PHI involved included names, addresses, phone numbers, and other identifiers. The BA notified HHS, the affected individuals, and the media. In its mitigation efforts, the BA revised its policies and procedures and implemented additional administrative and security safeguards.

What is known

People affected529 (as reported to HHS)
DisclosedJul 25, 2025
HappenedJul 14, 2025
AttackInsider
Data exposedNames, Health
SectorNonprofit · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CAJul 25, 2025
HHS archivetotalJul 25, 2025529

Other breaches at Valley Mountain Regional Center

BreachAffected
Disclosed Sep 29, 2023Sep 29, 20232 years agoHacking127K
Disclosed Nov 9, 2021Nov 9, 20214 years agoHacking17K
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 529 · backfill source
  • 2026-09-25 · summary: empty to Valley Mountain Regional Center, the business associate (BA), reported that an employee posted the protected health information (PHI) of 529 individuals on its website. The PHI involved included names, addresses, phone numbers, and other id · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Valley Mountain Regional Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.