Sunshine Behavioral Health Group LLC
ent_019e1f4ce4c2506c08e9a2b1af2b56cb
Disclosures
4
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
197,507
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sunshine Behavioral Health Group LLC
- Normalized
- sunshine behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900E0NPKL5IKQDF14
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- TEXASHHS OCRas victim2025-08-19
Behavioral Health Group reported to HHS on 2025-08-19 a Hacking/IT Incident affecting 597 individuals. Breached information located on Email. An employee was the subject of an email phishing scam that affected the protected health information (PHI) of approximately 597 individuals. The PHI involved included clinical information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals and implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.
- TEXASHHS OCRas victim2022-07-27
BHG Holdings, LLC dba Behavioral Health Group reported to HHS on 2022-07-27 a Hacking/IT Incident affecting 197,507 individuals. Breached information located on Network Server. The incident involved a ransomware attack compromising PHI including names, driver's licenses, SSNs, financial info, diagnoses, lab results, and medications.
- 🦬Montana State AGas victim2020-01-21
Sunshine Behavioral Health Group, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2020-01-21. The breach occurred from 9/4/2019 to 11/14/2019. 21 Montana residents were affected.
- 🐻California State AGas victim2020-01-21
Sunshine Behavioral Health Group, LLC notified individuals that a cloud-based system storing patient records was inadvertently configured to allow public internet access. The company became aware of the misconfiguration on September 4, 2019, and immediately changed settings and removed records from general access. Affected data included names, addresses, credit/debit card numbers, expiration dates, security codes, and electronic signatures. The company offered 24 months of identity protection services.