Sunshine Behavioral Health Group LLC
ent_019e1f4ce4c2506c08e9a2b1af2b56cb
Disclosures
9
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
197,507
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sunshine Behavioral Health Group LLC
- Normalized
- sunshine behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900E0NPKL5IKQDF14
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- TEXASHHS OCRas victim2025-08-19
Behavioral Health Group reported to HHS on 2025-08-19 a Hacking/IT Incident affecting 597 individuals. Breached information located on Email. An employee was the subject of an email phishing scam that affected the protected health information (PHI) of approximately 597 individuals. The PHI involved included clinical information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals and implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.
- TEXASHHS OCRas reporting2022-07-27
BHG Holdings, LLC dba Behavioral Health Group reported to HHS on 2022-07-27 a Hacking/IT Incident affecting 197,507 individuals. Breached information located on Network Server. The incident involved a ransomware attack compromising PHI including names, driver's licenses, SSNs, financial info, diagnoses, lab results, and medications.
- New Hampshire State AGas victim2020-01-22
Sunshine Behavioral Health Group, LLC notified the NH AG of a privacy incident where a cloud-based system storing patient records was inadvertently made publicly accessible on the internet. Discovered Sept 4, 2019, the breach affected PHI and payment info of 13 NH residents. Sunshine remediated access controls and offered 2 years of credit monitoring.
- Montana State AGas victim2020-01-21
Sunshine Behavioral Health Group, LLC notified Montana regulators of a misconfiguration incident where a cloud-based system storing patient records was inadvertently made available on the Internet. The breach affected PHI including SSNs, clinical data, and financial info. Sunshine discovered the incident on September 4, 2019, secured the system, and offered 24 months of credit monitoring.
- California State AGas victim2020-01-21
Sunshine Behavioral Health Group, LLC notified individuals that a cloud-based system storing patient records was inadvertently configured to allow public internet access. The company became aware of the misconfiguration on September 4, 2019, and immediately changed settings and removed records from general access. Affected data included names, addresses, credit/debit card numbers, expiration dates, security codes, and electronic signatures. The company offered 24 months of identity protection services.
- Massachusetts State AGas victim2020-01-21
Sunshine Behavioral Health Group, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-01-21. 56 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2020-01-01
SUNSHINE BEHAVORIAL HALTH GROUP LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-016). The register records the breach as discovered on December 23, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
SUNSHINE BEHAVORIAL HALTH GROUP LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-017). The register records the breach as discovered on September 4, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- CALIFORNIAHHS OCRas victim2019-12-02
Sunshine Behavioral Health Group, LLC reported to HHS on 2019-12-02 a Unauthorized Access/Disclosure affecting 3638 individuals. Breached information located on Network Server. A cloud-based system was improperly set up, exposing ePHI including names, SSNs, DOB, and health/financial data.