A Chicopee, Massachusetts, nonprofit that provides addiction recovery and developmental disability services has agreed to settle a class action over a 2024 hack that exposed client records. Behavioral health records carry a particular kind of exposure: a psychiatric diagnosis, a medication list or a treatment note can shadow a patient for years, and the stigma around them can outlast the breach itself.
The Mental Health Association, the agency behind those programs, said attackers reached its network in November 2024. Information caught up in the incident includes names, addresses and dates of birth, Social Security and driver’s license numbers, plus clinical detail such as diagnoses, medications and medical record numbers. Notices reached 12,633 people on May 30, 2025, roughly six months after the intrusion.
A class action followed in June 2025, accusing the nonprofit of negligence and of failing to maintain reasonable safeguards. A judge declined to dismiss the case, and two more plaintiffs joined. The suit, Campbell et al. v. Mental Health Association, Inc., remains pending in Hampden County Superior Court.
The nonprofit disputes every allegation and says the deal spares it the cost, risk and distraction of prolonged litigation. Benefits are capped at $300,000 and paid pro rata if that total is exceeded, and class members may claim up to $5,000 for documented losses or accept a one-time $40 payment, along with three years of credit monitoring. Claims are due November 19, 2026, ahead of a fairness hearing on December 15, 2026.
Mental health providers sit on some of the most intimate data in medicine, and extortion crews keep targeting them because modest operating budgets often mean thinner defenses.