Psychiatry & Holistic Health Center, a Norwell, Massachusetts mental health practice, discovered unauthorized activity in a staff account on its TherapyNotes system in October 2026. The breach exposed patient names, billing, insurance and payment card information, and confirmed unauthorized card charges occurred. Affected patients should monitor card statements, review insurance claims, and consider a credit freeze right away.
| Company | Psychiatry & Holistic Health Center |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names, Billing Information, Payment Records, Insurance Information, Health Care Record Details, Payment Card Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Account Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Psychiatry & Holistic Health Center Data Breach?
Psychiatry & Holistic Health Center, a mental health practice based in Norwell, Massachusetts, has told patients that someone gained unauthorized access to a staff account. The account lived inside TherapyNotes, the electronic health record and billing platform the practice relies on for daily operations. This means the activity was tied to a single login rather than to a wider breach of the practice’s own internal network.
According to the notice, the practice discovered the unauthorized account activity in October 2026. The letter does not say when the activity actually began, so the full timeline remains unclear. As a result, patients cannot know for certain how long an outsider may have had access before anyone noticed.
Once discovered, the practice says it moved to investigate. It contacted TherapyNotes directly, preserved account and payment-processing records, and reviewed what the unauthorized user may have viewed or touched. In addition, staff were required to change passwords, and the practice turned on two-factor authentication to block further unauthorized logins. The practice has said its review is ongoing and that it will share updates if new information changes what has been reported so far.
Who was affected?
The people affected by this incident are patients of Psychiatry & Holistic Health Center. Because the practice provides psychiatric and holistic mental health services, this breach touches a population that may already feel vulnerable about the privacy of their care.
The exact number of affected patients has not been publicly disclosed. The notice was filed with Massachusetts regulators, which suggests at least some patients live in or received care in that state. However, the letter does not rule out patients from other locations, since many practices treat people from neighboring states as well.
It is also worth noting the letter does not describe the affected group by age, so it is unclear whether minors who received care at the practice could be included. Because billing records often include a guarantor’s information, family members tied to a patient’s account could also be affected even if they were not direct patients themselves.
What Information Was Potentially Exposed?
The practice’s notice describes a narrow but still sensitive set of exposed data. Importantly, the letter states that Social Security numbers have not been identified as involved at this time, though the practice notes this could change as its investigation continues.
- Patient names
- Billing information
- Payment records
- Insurance information
- Health care record details
- Payment card information tied to unauthorized transactions
Even without Social Security numbers, this combination of data carries real risk. For example, insurance information can be used to commit medical identity theft, where a criminal uses someone else’s insurance details to obtain treatment or equipment. This can leave victims with incorrect medical records or unexpected bills.
In addition, the confirmed unauthorized payment card transactions raise an immediate financial concern. Because a mental health practice’s billing data links a patient’s name directly to behavioral health treatment, exposure here can also carry a privacy harm beyond typical financial fraud. This makes vigilance especially important for anyone who received this notice.
What is the company doing?
Once it discovered the unauthorized account activity, Psychiatry & Holistic Health Center says it began an internal investigation right away. The practice reports that it reached out to TherapyNotes to address the compromised account and preserved relevant records tied to the incident and to payment processing.
As part of its response, the practice required staff to reset passwords and enabled two-factor authentication across accounts. This is meant to reduce the chance that a similar login compromise could happen again. The practice also recommends that any patient who notices unauthorized card charges contact their card issuer immediately to dispute them.
Looking ahead, the practice says its investigation is still active. It has committed to notifying patients again if it discovers new details that change what has already been reported, such as whether Social Security numbers were ultimately involved.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone who received this notice should request a free copy of their credit report from each of the three major bureaus. You can do this through annualcreditreport.com at no cost. Reviewing these reports regularly helps you spot new accounts or inquiries you did not authorize.
Because billing and insurance information was involved, it is worth checking your reports more than once over the next year. Identity thieves sometimes wait months before using stolen data, so a single check right after notification is not enough on its own.
Consider a Fraud Alert or Credit Freeze
Even though Social Security numbers have not been identified as exposed, placing a fraud alert or credit freeze with Equifax, Experian and TransUnion adds a strong layer of protection. A freeze makes it much harder for anyone to open new credit in your name without your explicit approval.
This step is especially useful if the investigation later finds that more sensitive data, such as a Social Security number, was actually involved. Setting up a freeze now means you are already protected if that update comes later.
Watch for Medical and Insurance Fraud
Because health care record and insurance information were involved, patients should review any insurance statements they receive for unfamiliar claims. Medical identity theft can be harder to detect than financial fraud because it often shows up as an insurance explanation of benefits rather than a credit alert.
If you spot any service listed that you did not receive, contact your insurance provider right away. Reporting it quickly can help limit the damage to your medical record and your coverage history.
Stay Alert for Phishing Attempts
After any health care data breach, scammers often send emails or texts pretending to be the breached organization. Be cautious of any message asking you to click a link or confirm personal details, even if it references the practice by name.
Instead of clicking links in unexpected messages, go directly to the organization’s official website or call a verified phone number. This simple habit can prevent a secondary scam from compounding the original breach.
Review Your Payment Card Statements Closely
Since the practice confirmed unauthorized payment card transactions occurred, anyone who paid by card should review recent statements carefully. Look for charges you do not recognize, even small ones, since fraudsters sometimes test a card with a minor charge before making larger purchases.
If you find anything suspicious, contact your card issuer immediately to dispute the charge and request a replacement card. Acting quickly limits your liability and helps stop further misuse of the compromised card number.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
