Compass Behavioral Health
ent_8be93c3c36279c2a584596cd
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
537
as filed · HHS OCR KS
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Compass Behavioral Health
- Normalized
- compass behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🍁Vermont State AGas victim2025-04-21
Horizon Behavioral Health disclosed a ransomware incident discovered on March 16, 2025, with activity starting around March 13, 2025. The breach impacted patient demographic data (SSN, DL), clinical information, and insurance claims. Horizon engaged forensic experts, notified the FBI and CISA, and provided complimentary identity monitoring to affected individuals.
- 🦬Montana State AGas victim2025-04-21
Horizon Behavioral Health reported a data breach to the Montana Attorney General. The breach was reported on 2025-04-21. The breach occurred from 3/13/2025 to 3/16/2025. 6 Montana residents were affected.
- KSHHS OCRas victim2023-02-10
Compass Behavioral Health (KS) reported to HHS on 2023-02-10 a Hacking/IT Incident affecting 537 individuals. Several employees were targets of an email phishing attack that compromised PHI including names, addresses, dates of birth, and diagnoses/conditions. Breached information was located in Email. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. Additional security safeguards were implemented and workforce members were retrained. OCR provided technical assistance.