Richmond Behavioral Health Authority
ent_aed674c6c5f93803ddf6fde7
Disclosures
7
State AG · HHS OCR · Leak Site · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
113,232
nationwide · HHS OCR VA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Richmond Behavioral Health Authority
- Normalized
- richmond behavioral health authority— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rbha.org
Disclosure history (7)newest first
- Massachusetts State AGas victim2025-12-17
Richmond Behavioral Health Authority reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-17. 29 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-12-16
Richmond Behavioral Health Authority (RBHA) notified the New Hampshire Attorney General on December 9, 2025, of a ransomware incident. Malicious actors accessed RBHA's network on or about September 29, 2025, and deployed ransomware on September 30, 2025. A limited set of data, including names, SSNs, passport numbers, financial account info, and health information, was potentially accessed. Approximately 4 New Hampshire residents are estimated to be affected. RBHA engaged forensic experts, notified law enforcement, terminated access, and provided Kroll identity monitoring services.
- Montana State AGas victim2025-12-09
Richmond Behavioral Health Authority notified Montana residents of a ransomware incident discovered on September 30, 2025. Malicious actors accessed the network on September 29, 2025, deploying ransomware. Potential exposure includes names, SSNs, passport numbers, financial account info, and health information. Access was terminated; investigation ongoing. Kroll identity monitoring offered.
- Nebraska State AGas victim2025-12-04
Richmond Behavioral Health Authority (RBHA) notified Nebraska residents of a ransomware incident discovered on September 30, 2025. Malicious actors gained access on September 29, 2025, and encrypted portions of the network. RBHA terminated access and engaged forensic experts. While no definitive evidence of data misuse exists, affected individuals may have had names, SSNs, passport numbers, financial accounts, or health information exposed. RBHA provided Kroll identity monitoring services.
- Indiana State AGas victim2025-12-04
Richmond Behavioral Health Authority reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-29 and was reported on 2025-12-04. 9 Indiana residents were affected. 109,411 individuals affected in total.
- VIRGINIAHHS OCRas victim2025-11-28
Richmond Behavioral Health Authority reported to HHS on 2025-11-28 a Hacking/IT Incident affecting 113232 individuals. Breached information located on Network Server.
- GLOBALLeak Siteas victim2025-10-15
Richmond Behavioral Health Authority (RBHA) is a statewide organization dedicated to providing comprehensive mental health, mental retardation, substance abuse and prevention services to the residents of the City of Richmond. The organization ...