Provident Behavioral Health, a St. Louis-area mental health provider, detected unauthorized access to its systems on April 3, 2026. Patients weren’t notified until early September — nearly five months later, and the exposed data includes Social Security numbers and medical information.
Provident Behavioral Health, a nonprofit mental health organization with locations across the St. Louis, Missouri area, has notified patients of a data breach. According to the organization’s own notice, Provident detected suspicious activity on its computer systems on April 3, 2026 and determined that an unauthorized party had accessed and acquired data stored on its network. Provident reported the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on September 4, 2026, and began mailing individual notice letters around the same time — about five months after it first detected the intrusion.
Source: Provident Behavioral Health’s own Notice of Data Breach letter; Massachusetts Office of Consumer Affairs and Business Regulation breach notification filing 2026-1507 (reported 09/04/2026).
Care and Counseling Patients Are Also Affected
Provident’s notice specifies that the breach affects current and former patients of both Provident Behavioral Health and Care and Counseling, a separate organization that joined Provident in 2023. If you were previously a client of Care and Counseling and haven’t thought about that relationship in years, you may still be part of this breach — Provident’s notice letter is the way many affected people will learn their information was involved at all.
What Information Was Exposed?
According to Provident’s own notice letter, independently corroborated by Massachusetts’s own breach reporting, the exposed information includes:
- Full name
- Contact and demographic information
- Date of birth
- Driver’s license or state identification number
- Social Security number
- Medical information
- Health insurance information
Source: Provident Behavioral Health’s Notice of Data Breach letter; Massachusetts Annual Data Breach Notification Report (filing 2026-1507), which independently marks Social Security Numbers, Medical Records, and Drivers Licenses each ‘Yes’ for this filing.
How Many People Are Affected?
Provident has not disclosed a total number of affected patients. Massachusetts’s own filing confirms 11 Massachusetts residents, but that is only a small state-level subset — Provident’s own patient base is centered in and around St. Louis, and Missouri does not operate a public breach notification database that would supply a statewide figure. Given that Provident’s notice covers current and former patients of both Provident and Care and Counseling, the true number of people affected is likely well beyond the 11 confirmed in Massachusetts.
What Is Provident Offering Affected Patients?
According to Provident’s notice letter, the organization is offering twelve months of single-bureau credit monitoring, a single-bureau credit report, and a single-bureau credit score, along with fraud assistance services through HaystackID. Affected individuals generally must enroll within 90 days of the date on their letter to receive this coverage. Provident can be reached directly at 314-371-6500 or by mail at 2650 Olive Street, St. Louis, MO 63103.
Source: Provident Behavioral Health’s Notice of Data Breach letter.
Why Mental Health Data Makes This Especially Sensitive
Provident is a mental health provider, and the records involved include medical information for behavioral health patients — a category of information people generally consider deeply private. Combined with Social Security numbers and driver’s license numbers, the exposed data set creates risk not just of identity theft and financial fraud, but of a more personal kind of exposure for patients who sought mental health treatment through Provident or Care and Counseling.
Why the Five-Month Delay Matters
Missouri’s data breach notification statute requires notice ‘without unreasonable delay.’ Massachusetts’s own breach law uses similar language, requiring notice ‘as soon as practicable and without unreasonable delay.’ Provident’s own timeline — detection on April 3, 2026, and notice beginning roughly five months later in early September — is the kind of gap that a notification-delay claim is built on. Provident’s notice does not explain the reason for the delay.
Do You Have Legal Options?
Healthcare organizations that collect and store sensitive medical, financial, and personal information have a legal duty to secure it and to notify affected patients without unreasonable delay.
If you received a notice letter from Provident Behavioral Health or Care and Counseling, contact Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
FAQ
Who is affected by the Provident Behavioral Health data breach?
Current and former patients of Provident Behavioral Health and of Care and Counseling, an organization that joined Provident in 2023. Massachusetts’s filing confirms at least 11 residents there; the total number affected, centered on Provident’s St. Louis-area patient base, has not been disclosed.
What information was exposed?
According to Provident’s own notice letter, the exposed data includes names, contact and demographic information, dates of birth, driver’s license or state ID numbers, Social Security numbers, medical information, and health insurance information.
I was a patient of Care and Counseling, not Provident. Am I affected?
Possibly. Care and Counseling joined Provident Behavioral Health in 2023, and Provident’s notice specifically covers current and former patients of both organizations.
Why did it take five months to notify patients?
Provident detected the intrusion on April 3, 2026, but did not begin notifying patients or regulators until early September 2026 — roughly five months later. Provident’s notice does not explain the reason for the delay.
What is Provident offering affected patients?
According to Provident’s notice letter, twelve months of single-bureau credit monitoring, a credit report, and a credit score, plus fraud assistance through HaystackID, generally available if you enroll within 90 days of your letter date.
Do I have a legal claim?
Healthcare organizations that collect and store sensitive medical, financial, and personal information have a legal duty to secure it and to notify affected patients without unreasonable delay. If you received a notice letter from Provident Behavioral Health or Care and Counseling, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.