A Kissimmee nonprofit that runs mental health and addiction services has become the latest behavioral care provider to disclose a network intrusion. Osceola Mental Health, which does business as Park Place Behavioral Health Care, told regulators that an unauthorized party copied files from its systems.
The organization spotted unusual activity on July 23, 2026, then brought in an outside forensics firm. On August 19 the investigation concluded that data had been taken. Notification letters went out starting September 17, and Massachusetts Attorney General records show at least 52 residents of that state were caught up in the incident.
Exposed data varies by person but includes names, dates of birth, Social Security numbers, driver’s license or state ID numbers, financial account details, health insurance information, medical records and clinical treatment details.
Behavioral health breaches carry an extra sting. Substance use and psychiatric treatment histories are among the most sensitive categories a provider holds, and they are the kind of material that fuels extortion and secondary targeting long after the first incident. Park Place’s size also makes it typical of the sector: community nonprofits with lean budgets and aging infrastructure form the vulnerable middle of the healthcare market, and they increasingly absorb the same attacks aimed at large systems.
Attorneys are now investigating a possible class action. Affected patients should watch for the mailed notice, confirm what was exposed, and consider a credit freeze given the presence of Social Security numbers and financial data.
For other community providers the takeaways are unglamorous: segment networks so one compromised workstation cannot reach the file server, log access to the shares that hold treatment records, and rehearse the notification timeline before it is needed.