Loving and Living Center, PC dba Awakenings Center Data Breach
NC Mental Health Center Breach Exposes 17,800 Patient Records
What happened in the Loving and Living Center, PC dba Awakenings Center data breach?
The Loving and Living Center, PC dba Awakenings Center data breach was reported on November 7, 2025 and affected 17,800 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in North Carolina. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Loving and Living Center, PC dba Awakenings Center Breach Details
Healthcare Data Breach Report: Loving and Living Center, PC dba Awakenings Center
Incident Overview
Loving and Living Center, PC, operating under the name Awakenings Center, experienced a significant data breach affecting 17,800 individuals in North Carolina. The breach, classified as a hacking or IT incident, resulted in unauthorized access to the organization's Electronic Medical Record (EMR) system. The breach was formally reported to the U.S. Department of Health and Human Services on November 7, 2025, triggering mandatory HIPAA breach notification requirements. This incident represents a substantial compromise of patient privacy affecting a significant portion of the center's patient population and requires immediate attention from affected individuals.
Discovery and Response Timeline
While specific details regarding the initial discovery date are not provided in the breach submission, the November 7, 2025 submission date indicates that the organization completed its investigation and notification process within the HIPAA-mandated 60-day window from discovery. Upon identifying the unauthorized access to their EMR system, Awakenings Center initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what protected health information (PHI) may have been compromised. The organization was required to notify affected patients, the media (given the large number of affected individuals), and the HHS Office for Civil Rights as part of standard HIPAA breach notification procedures. The fact that no business associate was involved in this breach suggests the compromise occurred directly within the organization's own IT infrastructure or systems.
Technical Breach Details
This incident is classified as a hacking or IT incident, which typically involves unauthorized access to computer systems or networks through various technical means. Hacking incidents targeting healthcare organizations commonly involve methods such as exploitation of unpatched software vulnerabilities, credential compromise through phishing or social engineering, weak authentication mechanisms, or inadequate network segmentation. The specific targeting of the Electronic Medical Record system indicates that threat actors either directly accessed the EMR platform or gained sufficient network access to reach it. EMR systems are high-value targets for cybercriminals because they contain comprehensive patient information in a centralized, searchable format. The breach of an EMR system suggests the organization's network perimeter or internal security controls may have been insufficient to prevent or detect unauthorized access in a timely manner. Given the scale of affected individuals (17,800), this was likely not a limited, isolated incident but rather a sustained or broad compromise affecting multiple patient records or entire database segments.
Organizational Context
Awakenings Center is a mental health and behavioral health treatment facility operating in North Carolina. The organization's dual naming convention (Loving and Living Center, PC dba Awakenings Center) suggests it may be a professional corporation providing specialized mental health services. Mental health and substance abuse treatment centers typically maintain particularly sensitive patient information, including detailed psychiatric histories, medication records, treatment plans, and sometimes information related to substance abuse treatment—all of which carry heightened privacy concerns under HIPAA. The fact that the organization maintains a comprehensive EMR system indicates it is a reasonably sized operation with modern health IT infrastructure. However, the breach suggests that despite having electronic health records systems in place, the organization may have had gaps in cybersecurity controls, network monitoring, or incident response capabilities. Mental health providers often face unique cybersecurity challenges due to resource constraints compared to larger hospital systems, potentially making them attractive targets for threat actors.
Patient Impact and Affected Population
Approximately 17,800 individuals had their protected health information potentially accessed through this breach. This represents a substantial portion of the organization's patient population and indicates either a broad compromise of the EMR database or extended unauthorized access over a period of time. Patients affected by this breach likely include current and former patients of Awakenings Center who had records stored in the compromised EMR system. The notification process, required under HIPAA's Breach Notification Rule, mandates that each affected individual receive written notice of the breach, the types of information involved, steps the organization is taking to investigate and mitigate the breach, and recommended actions patients should take to protect themselves. Given the mental health nature of the organization, affected individuals may experience heightened concern about the exposure of sensitive psychiatric and behavioral health information.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities must notify affected individuals of breaches of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery of the breach. The November 7, 2025 submission date suggests Awakenings Center met this requirement. Additionally, the organization must notify prominent media outlets and the HHS Office for Civil Rights. Breaches affecting 500 or more residents of a state or jurisdiction require media notification, and this breach clearly exceeds that threshold. Hacking and IT incidents represent a growing category of healthcare data breaches, with the HHS Office for Civil Rights reporting that such incidents consistently account for a significant percentage of reported breaches. The healthcare industry has experienced an increase in sophisticated cyberattacks targeting patient data, with threat actors recognizing the value of medical records on the dark web. Mental health records command premium prices in criminal markets due to their sensitivity and the potential for blackmail or identity theft. Organizations in the behavioral health sector should implement strong cybersecurity measures including multi-factor authentication, network segmentation, regular security assessments, employee security training, and comprehensive incident response plans.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Loving and Living Center, PC dba Awakenings Center Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for signs of fraudulent activity; consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized medical services or prescriptions; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Change passwords for any online accounts associated with Awakenings Center or your healthcare providers, using strong, unique passwords; enable multi-factor authentication where available
Be vigilant against phishing emails, text messages, or phone calls that may reference your mental health treatment or insurance information; do not click links or provide information in response to unsolicited communications claiming to be from healthcare providers or insurers
Consider placing a fraud alert or credit freeze with credit bureaus and monitor your credit for the next 12-24 months; consider enrolling in credit monitoring or identity theft protection services if offered by the organization
Document all communications with Awakenings Center regarding the breach and retain copies of breach notification letters for your records
Contact the organization directly using verified contact information to confirm what specific information was compromised and what remediation steps they are taking
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More North Carolina Breaches
Search all breaches reported in North Carolina
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits