Psychiatric Wellness Center breach: was your mental health data accessed?
If you were named in this filing, here’s what is being claimed, and what it would mean for you.
A Bakersfield psychiatric practice, Kern Psychiatric Health and Wellness Center (Psychiatric Wellness Center), confirmed that patient files on its management company’s computers were accessed without authorization. Those files may have included names plus Social Security numbers and mental-health treatment details, among other information. The practice has not said how many people were affected and says it does not believe the information was misused.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
What’s already out there about you?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On June 22, 2026, Genesis Healthcare Management, which runs computer systems for Kern Psychiatric Health and Wellness Center, Inc. — a Bakersfield psychiatric practice also called Psychiatric Wellness Center — found unusual activity on its network. An investigation with outside specialists concluded that some files on that network, which held certain patient data from the practice, had been accessed without authorization. The California Attorney General lists the date of the breach as April 16, 2026. The practice’s own notices describe the June 22 discovery.
Notice letters were dated August 19, 2026. A sample was filed with the California Attorney General and recorded on August 21, 2026, and a notice was posted on the practice’s website. Information that may have been involved, which differed from person to person, included a name together with one or more of the following, if it had already been given to the practice: Social Security number, driver’s license or other government ID number, date of birth, diagnosis and treatment information, prescription information, provider name and location, dates of service, medical record number, patient account number, Medicare or Medicaid ID number, lab results, and health insurance information. The practice did not say how many people were affected. It said Genesis re-secured the data, that the data was not distributed, and that it has no reason to believe any information has been or will be misused. It offered 12 months of credit monitoring through Cyberscout.
They offered credit monitoring. The files were about psychiatric care.
There is no independent news investigation of this. The detailed account in public is the practice’s own letter. That letter is built around reassurance: the network was locked down again, the data was not passed along, nothing appears to have been misused, and credit monitoring is available if you want it.
What that framing leaves in the background is what kind of office this is. Psychiatric Wellness Center is a mental-health practice. For some people, the accessed files could place a real name next to a diagnosis, treatment information, prescriptions, lab results, and the clinic involved — and, for some, a Social Security number or driver’s license number as well. Credit monitoring watches for new borrowing in your name. It does not tell you who saw that you received psychiatric care, and it does not make that fact less sensitive.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
Unauthorized access is not the same as your records being posted for the world. The practice says it does not believe the information was distributed, and there is no public evidence that it was published or used to commit fraud. That is worth taking at its word, as far as it goes. It is also worth being clear-eyed: someone who was not supposed to open those files did. The practice has not said how many patients were involved, or how long the access lasted. A psychiatric record attached to an identity is not something you can cancel. That is the part of the story the letter is not built to sit with.
What to actually expect
- If the practice concluded you were potentially affected, a letter dated August 19, 2026, offering 12 months of Cyberscout credit monitoring. Letters are easy to miss, and the practice never published a number of people. The only party that knows whether it sent you a notice is the practice itself.
- Follow-on phishing that copies the real notices. Those notices are on the practice’s website and in California’s public breach filings, so a fake message that uses the clinic’s name, Genesis, Cyberscout, or the Attorney General to ask for a login, a code, or more personal information is the most likely “next thing” to show up.
- No public roster, no official headcount, and no website that can tell you whether your file was among those accessed. That figure was never released, and a clean result from some other search would not prove you were left out.
- No confirmed wave of fraud and no public dump of records, based on what the practice has said and what is on file with the state. If misuse happens, the version that fits the data involved is someone quietly using a Social Security number or an insurance or Medicare ID — not your diagnosis appearing in a headline.
What you can and cannot fix
If your information was in the files that were accessed, that cannot be undone. A Social Security number or driver’s license number cannot be recalled. A diagnosis, a prescription history, or a lab result cannot be un-seen. No service can delete what an unauthorized person already opened, and anyone who promises to remove the breached data is promising something that is not possible.
- If this practice had your Social Security number, freeze your credit. A freeze at the major credit bureaus is what actually blocks new accounts in your name. Treat that number as permanently exposed if it was in your file; you cannot take it back. The free Cyberscout year, if you received the letter, can alert you after something happens. It is a backup, not the main control, and it does nothing for medical privacy.
- Read insurance, Medicare, and Medicaid mail for care you did not receive. For some people this incident included health insurance numbers and Medicare or Medicaid IDs. That is a medical-billing problem, not a credit-card problem, and it will show up on explanations of benefits, not on a credit report.
- Ignore unexpected links and attachments that name this clinic. The genuine notice was a letter and a website posting. A message that demands you “verify” your Social Security number, insurance ID, or Cyberscout enrollment to “see if you were affected” is using this event against you.
- Remove the extra personal details that people-search sites publish about you. A clinic file with a name, date of birth, and identity numbers becomes much more useful to a stranger when it can be joined to listings that add relatives, phone numbers, employers, and previous addresses. Those listings are not the patient file — and unlike that file, they can actually be taken down. Reducing that public footprint is one of the few levers that is still in your hands.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Psychiatric Wellness Center.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Tixel data breach: your email and mobile number may have been accessed
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been…
Manchester Airports Group data breach: 8.7 million customer records accessed
Manchester Airports Group has confirmed that an unauthorised party accessed customer data from airpo…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…