On August 11, 2025, the qilin ransomware group listed the Charak Center for Health on its leak site and began publishing what it claims are the organization’s internal files. The Ohio-based mental health and addiction treatment provider serves thousands of patients across northeastern Ohio with psychiatric care, counseling, and substance-abuse programs. Any patient or employee whose records passed through the center in recent years may now have sensitive personal information at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates that qilin claims to have exfiltrated internal company data during a ransomware attack. The leak site lists Charak Health and Wellness Center and has started releasing samples of the allegedly stolen files. No exact patient count has been disclosed, and the precise volume and sensitivity of the documents remain unconfirmed by independent third parties. The incident follows the group’s typical pattern of encrypting systems, exfiltrating data, then threatening to publish it unless a ransom is paid.
Why This Matters for You and Your Family
If you or a family member has ever received mental health care, addiction treatment, or counseling at Charak, your medical history, contact details, insurance information, and possibly Social Security numbers could be among the files now circulating on a criminal leak site. Mental-health records are especially damaging when exposed because they can affect employment, insurance coverage, child-custody disputes, and personal relationships for years. Even if you were not a direct patient, an employee’s payroll file or a family member’s intake form can contain enough details to open the door to identity theft or harassment.
The Doxxing and Identity-Chain Implications
Medical breaches rarely stop at the initial leak. Criminal actors combine exposed names, addresses, phone numbers, and email accounts with credential leaks from other services to build detailed identity profiles. A single reused password found in the Charak files can lead to takeover of email, banking, or social-media accounts. When children’s or teenagers’ information appears—sometimes through a parent’s insurance record or a family counseling file—the risk extends to their gaming accounts and online handles, creating long-term doxxing chains that are difficult to untangle without specialized help.