COMHAR, Inc., a Philadelphia nonprofit that has provided behavioral health and human services since 1975, has notified clients that a hacker copied files from its network — including treatment notes, diagnoses, and medications.
COMHAR, Inc., a long-established nonprofit serving greater Philadelphia with behavioral health, intellectual disability, and home health care programs, has published a substitute breach notice stating that an unknown actor copied files and folders from its network on or before July 17, 2026. COMHAR’s notice, published as a legal notice in The Philadelphia Inquirer, states that its review of the affected files is ongoing and that notification to individuals is in process.
What Information Was Exposed?
According to COMHAR’s own notice, the information involved includes:
- Full name
- Address
- Date of birth
- Social Security number
- Treatment notes
- Diagnoses
- Medications
- Health insurance information
For a behavioral health provider, the inclusion of treatment notes, diagnoses, and medication information is especially significant. This is not just financial information — it is a record of a person’s mental health care, which many people consider among the most private information they have.
A Ransomware Group’s Claim — Not Yet Confirmed by COMHAR
A group calling itself World Leaks listed COMHAR on its dark web extortion portal, and separate cybersecurity researchers have reported that stealer-log monitoring showed exposed credentials tied to COMHAR’s own domain, including access to its Microsoft identity and email systems. COMHAR has not confirmed the identity of the group responsible or the specifics of this reporting in its own public notice, and Emery | Reddy is presenting this only as an unverified claim from outside sources — not a fact confirmed by COMHAR.
Source: SOCRadar Cyber Intelligence, reporting on the World Leaks extortion portal listing and stealer-log telemetry for the comhar.org domain; this reporting is independent of, and has not been confirmed by, COMHAR’s own notice.
How Many People Are Affected?
COMHAR has not disclosed a total number of affected individuals, and its notice states that its review of the affected data is still ongoing. No state regulator database currently lists a population figure for this incident — Pennsylvania does not operate a public breach notification database, which is a common gap for organizations based there. Given COMHAR’s size as a multi-service provider running residential, outpatient, and intellectual disability programs across greater Philadelphia, the number of people affected is plausibly in the thousands, though no figure has been confirmed.
Why the Delay Matters
COMHAR’s own notice describes the file copying as occurring ‘on or before July 17, 2026’ — language that leaves open the possibility the actual intrusion began earlier. Measured from that date alone, at least 53 days passed before the notice became public in early September 2026. Pennsylvania’s Breach of Personal Information Notification Act requires notice without unreasonable delay. For a behavioral health provider whose exposed records include treatment notes and diagnoses, prompt notice matters even more than usual — those are exactly the records whose exposure is most sensitive to the people affected.
Do You Have Legal Options?
Healthcare and human-services organizations that collect and store sensitive medical and personal information have a legal duty to secure it and to notify affected individuals without unreasonable delay.
If you received a notice about this breach, or you are a current or former COMHAR client, contact Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
FAQ
Who is affected by the COMHAR data breach?
COMHAR has not disclosed a total number. The organization serves clients across greater Philadelphia through residential, outpatient, and intellectual disability programs, and its notice states that review of the affected data is ongoing.
What information was exposed?
According to COMHAR’s own notice, the exposed data includes names, addresses, dates of birth, Social Security numbers, treatment notes, diagnoses, medications, and health insurance information.
Has a hacking group claimed responsibility?
A group calling itself World Leaks has listed COMHAR on a dark web extortion site, and outside cybersecurity researchers have reported related credential exposure. COMHAR has not confirmed this claim in its own notice, so Emery | Reddy is treating it as unverified.
Why does it matter that treatment notes and diagnoses were exposed?
Behavioral health records are among the most sensitive categories of personal information. Exposure of treatment notes, diagnoses, and medications carries a different kind of risk than a typical data breach — beyond financial fraud, it can expose deeply private details about a person’s mental health care.
Do I have a legal claim?
Healthcare and human-services organizations that collect and store sensitive medical and personal information have a legal duty to secure it and to notify affected individuals without unreasonable delay. If you received a notice about this breach, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.