New Creation Counseling Center Data Breach
New Creation Counseling Center Network Breach Affects 24,000+
What happened in the New Creation Counseling Center data breach?
The New Creation Counseling Center data breach was reported on April 14, 2022 and affected 24,029 individuals. The breach type was Hacking/IT Incident involving Network Server, Other. This breach occurred in Ohio. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
New Creation Counseling Center Breach Details
Healthcare Data Breach Report: New Creation Counseling Center
Incident Overview
New Creation Counseling Center, a mental health and counseling services provider based in Ohio, experienced a significant data breach involving unauthorized access to its network infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on April 14, 2022, affecting approximately 24,029 individuals. The incident involved compromise of the organization's network server and related IT systems, exposing sensitive patient health information and personal data maintained by the counseling center. This type of breach represents a serious threat to patient privacy, particularly given the sensitive nature of mental health records and the trust patients place in counseling providers.
Discovery and Response Timeline
While the exact discovery date is not specified in the breach notification submission, New Creation Counseling Center identified the unauthorized access to its network systems and initiated an investigation into the scope and nature of the compromise. Following discovery, the organization conducted a forensic investigation to determine what data had been accessed, which individuals were affected, and the extent of the breach. The organization notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured protected health information (PHI). The April 14, 2022 submission date to HHS indicates the organization met its regulatory notification obligations by reporting the breach to federal authorities as required.
Technical Details of the Breach
The breach involved unauthorized access to New Creation Counseling Center's network server infrastructure, classified as a "hacking/IT incident" in the breach notification. Network server compromises typically occur through one or more of several common attack vectors: exploitation of unpatched software vulnerabilities, weak or compromised credentials, phishing attacks targeting staff members, misconfigured security settings, or inadequate network segmentation. The "Other" location designation suggests the breach may have involved multiple systems or access points beyond the primary network server. Hacking incidents of this nature often result from sophisticated threat actors targeting healthcare organizations specifically for the high value of patient data on the black market. Mental health records are particularly valuable to criminals due to the sensitive nature of the information and the potential for identity theft, insurance fraud, or blackmail. The fact that no business associate was involved indicates the breach occurred within New Creation Counseling Center's own IT infrastructure rather than through a third-party vendor or service provider.
Organizational Context
New Creation Counseling Center operates as a mental health and counseling services provider in Ohio, serving patients seeking psychological counseling, therapy, and related behavioral health services. As a counseling center, the organization maintains detailed clinical records including patient psychiatric histories, treatment notes, diagnoses, medication information, and other sensitive mental health data. The organization's service area encompasses Ohio, with the breach affecting a substantial patient population of over 24,000 individuals. This scale suggests New Creation Counseling Center operates multiple locations or serves a large geographic area within the state. Mental health providers like counseling centers are increasingly targeted by cybercriminals due to the sensitivity of their records and the likelihood that patients will pay to prevent disclosure of their mental health information.
Impact on Affected Individuals
Approximately 24,029 patients and individuals associated with New Creation Counseling Center had their protected health information potentially exposed in this breach. The affected population includes current and former patients who received counseling or mental health services from the organization. These individuals were notified of the breach and informed about the types of information that may have been accessed. Given the nature of a network server compromise, the exposed data likely includes a broad range of personal and health information maintained in the organization's electronic health record (EHR) systems and related databases. Patients affected by this breach face potential risks including identity theft, unauthorized use of their health information, and privacy violations related to their mental health treatment.
HIPAA Compliance and Regulatory Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities like New Creation Counseling Center must notify affected individuals of breaches of unsecured PHI. The rule requires notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. Additionally, covered entities must notify prominent media outlets if the breach affects more than 500 residents of a state or jurisdiction, and must notify the HHS Secretary. Network server breaches represent one of the most common categories of healthcare data breaches, accounting for a significant percentage of reported incidents annually. According to HHS breach notification data, hacking and IT incidents consistently rank among the top causes of healthcare data breaches, often affecting large numbers of individuals due to the centralized nature of network infrastructure. The 24,029 individuals affected in this incident places it in the regional impact category, representing a substantial breach requiring coordinated notification efforts and regulatory reporting.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the New Creation Counseling Center Breach
Monitor credit reports and financial accounts closely for signs of fraudulent activity. Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review them for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the credit bureaus to prevent unauthorized account opening.
Change passwords for all online accounts, particularly healthcare portals, email accounts, and financial accounts. Use strong, unique passwords containing a mix of uppercase and lowercase letters, numbers, and special characters. Enable multi-factor authentication wherever available to add an additional layer of security.
Monitor healthcare accounts and explanation of benefits (EOB) statements for unauthorized claims or services. Contact your insurance provider and healthcare providers if you notice any claims or services you did not authorize. Request copies of your medical records to verify accuracy.
Consider enrolling in credit monitoring and identity theft protection services if offered by New Creation Counseling Center as part of their breach response. Many organizations provide complimentary monitoring services for affected individuals. Be cautious of unsolicited offers and verify any services through official breach notification communications.
Report any suspicious activity to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if you become a victim of identity theft or fraud. Document all fraudulent activity and maintain records of communications with creditors and financial institutions.
Contact New Creation Counseling Center directly with questions about the breach, what information was exposed, and what protective measures they are implementing. Request written confirmation of the types of data exposed and the organization's remediation efforts.
Be cautious of phishing emails or calls claiming to be from New Creation Counseling Center or offering identity protection services. Verify communications by contacting the organization directly using phone numbers or websites from official sources, not from unsolicited communications.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Ohio Breaches
Search all breaches reported in Ohio
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits