OCAT, LLC dba Evoke Wellness at Hilliard Data Breach
OCAT Evoke Wellness EMR Breach Affects 1,629 Patients
What happened in the OCAT, LLC dba Evoke Wellness at Hilliard data breach?
The OCAT, LLC dba Evoke Wellness at Hilliard data breach was reported on December 12, 2025 and affected 1,629 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record. This breach occurred in Ohio. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
OCAT, LLC dba Evoke Wellness at Hilliard Breach Details
Healthcare Data Breach Report: OCAT, LLC dba Evoke Wellness at Hilliard
Incident Overview
OCAT, LLC, operating as Evoke Wellness at Hilliard in Ohio, experienced an unauthorized access incident involving its Electronic Medical Record (EMR) system. The breach was formally reported to the Ohio Attorney General on December 12, 2025, affecting 1,629 individuals. This incident represents a significant compromise of patient privacy within a behavioral health and wellness treatment facility. The unauthorized access to the EMR system created potential exposure of sensitive protected health information (PHI) maintained within the organization's digital infrastructure.
Discovery and Response Timeline
While specific discovery dates are not detailed in the breach submission, OCAT initiated an investigation upon identifying the unauthorized access to its EMR system. The organization conducted a comprehensive review of affected records and determined the scope of the breach to include 1,629 patients. Following standard HIPAA breach notification requirements, OCAT began the process of notifying affected individuals of the incident. The December 12, 2025 submission date indicates the organization met its obligation to report the breach to state authorities within the required 60-day notification window. The entity's response included securing the affected systems and implementing measures to prevent similar incidents.
Technical Details of the Breach
The breach involved unauthorized access to OCAT's Electronic Medical Record system, which typically houses comprehensive patient health information including clinical notes, treatment plans, medication records, and diagnostic information. EMR systems are primary targets for healthcare data breaches because they contain consolidated, high-value patient data in a single digital location. Unauthorized access to such systems may have occurred through various vectors including compromised credentials, exploitation of software vulnerabilities, inadequate access controls, or insider threats. The fact that this breach involved the EMR directly—rather than peripheral systems—suggests the unauthorized party gained access to core clinical documentation. This type of breach is particularly concerning because EMR systems often contain some of the most sensitive patient information available within a healthcare organization.
Organizational Context
Evoke Wellness at Hilliard operates as a behavioral health and wellness treatment facility located in Hilliard, Ohio. OCAT, LLC operates this facility as part of what may be a larger network of wellness and treatment centers. The organization provides mental health, substance abuse treatment, and wellness services to patients in the central Ohio region. As a healthcare provider maintaining electronic health records, OCAT is subject to HIPAA Security Rule requirements mandating safeguards for electronic PHI. The breach indicates that despite these regulatory requirements, the organization's access controls or security monitoring systems were insufficient to prevent or immediately detect unauthorized access to its EMR infrastructure.
Patient Impact and Affected Information
Approximately 1,629 patients had their protected health information potentially exposed through this unauthorized access incident. These individuals likely include current and former patients who received treatment at the Hilliard facility. The compromise of EMR data means that sensitive clinical information may have been accessed, potentially including psychiatric or substance abuse treatment records, medication lists, diagnoses, treatment plans, and other detailed health information. For patients receiving behavioral health services, the exposure of such information carries heightened privacy concerns due to the stigma and discrimination risks associated with mental health and addiction treatment records. Patients were notified of the breach and advised to monitor their information for potential misuse.
HIPAA Compliance and Industry Context
Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of breaches of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. OCAT's December 2025 submission indicates compliance with this timeline. The organization was also required to notify the Ohio Attorney General and, depending on the number of affected residents, potentially the media. Unauthorized access incidents involving EMR systems represent a significant category of healthcare data breaches. According to industry reports, healthcare organizations experience thousands of breach incidents annually, with unauthorized access and hacking representing the most common breach types. EMR systems are particularly vulnerable because they represent centralized repositories of high-value patient data. Organizations must implement multi-factor authentication, role-based access controls, comprehensive audit logging, and regular security assessments to protect against such incidents. The breach at OCAT reflects broader challenges healthcare organizations face in securing increasingly complex digital health infrastructure while maintaining operational efficiency.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the OCAT, LLC dba Evoke Wellness at Hilliard Breach
Monitor credit reports and financial accounts for unauthorized activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) if personal identifiers were exposed
Review the notification letter from OCAT carefully for specific information about what data was compromised and any complimentary credit monitoring or identity theft protection services offered
Change passwords for any online healthcare portals or accounts associated with OCAT and use strong, unique passwords; enable multi-factor authentication where available
Be cautious of unsolicited communications claiming to be from OCAT or healthcare providers; verify any requests for information directly by calling the organization's official phone number rather than using contact information in suspicious messages
Consider consulting with a privacy attorney if you have concerns about the exposure of sensitive behavioral health information and potential discrimination risks
Document the breach notification and maintain records of any identity theft or fraud attempts for potential future claims or legal action
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Ohio Breaches
Search all breaches reported in Ohio