LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Central Kansas Mental Health Center Data Breach Notice (Indiana Attorney General)

MEDIUM severityConfirmedHow we verify

Central Kansas Mental Health Center Data Breach Notice (Indiana Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 24, 2026
Central Kansas Mental Health Center Data Breach Notice (Indiana Attorney General)

Occurred September 21, 2025 · publicly disclosed June 24, 2026. Approximately 2 people affected.

MEDIUM
Severity
2
People affected
1
Data types exposed
June 24, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Central Kansas Mental Health Center disclosed a data breach on June 24, 2026, after unauthorized access exposed personal information of two individuals that occurred on September 21, 2025. If you received services from the center, review any notices you may have received and consider monitoring your accounts and credit reports.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
2 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A small number of people may have had personal information involved in a data security incident at Central Kansas Mental Health Center. Public notice to Indiana authorities places the event months before the formal report, and the filing names only a limited group as affected. For anyone who has received care or services connected to this organization, the practical question is whether their information was among what was exposed and what that could mean for identity and privacy risk.

According to a filing reported to the Indiana Attorney General on June 24, 2026, Central Kansas Mental Health Center notified Indiana residents of a data breach. The same filing dates the incident itself to September 21, 2025. The notice states that two people were affected and that personal information was involved. Beyond those points, public detail in the disclosure is limited.

What happened

Central Kansas Mental Health Center submitted a data breach notice that was reported to the Indiana Attorney General on June 24, 2026. In that filing, the organization placed the underlying incident on September 21, 2025. The reported figure for people affected is two. The breach notification describes the exposed material as personal information.

The public record available from this disclosure does not describe how the incident was discovered, what systems were involved, whether access was unauthorized electronic intrusion, misdirected records, insider misuse, or another cause, or what containment and notification steps followed day to day. Method, technical scope, and any fuller timeline beyond the incident date and the reporting date are undisclosed in the facts provided. The notice is framed as notification to Indiana residents, which indicates at least some affected individuals had a connection to that state for notice purposes, even though the organization itself is identified as Central Kansas Mental Health Center.

How a breach like this happens

In general terms, incidents that lead to breach notices in healthcare and behavioral-health settings often involve one of several familiar patterns. Attackers may obtain credentials through phishing or reused passwords and then reach email, patient portals, or administrative systems. Ransomware and related intrusion activity can encrypt or exfiltrate files from servers and backups. Lost or stolen devices, misaddressed correspondence, or errors by vendors who process billing and records can also expose personal data without a dramatic network attack. Sometimes a vulnerability in remote access or an unpatched application is used to reach stored files.

None of those scenarios is established as the cause of this specific incident. No threat group is attributed in the disclosure, and public detail does not confirm a particular technique. The background is offered only to explain how organizations of this type typically come to file notices when personal information may have been accessed or acquired without authorization, or when they cannot rule that out after an investigation.

Who is Central Kansas Mental Health Center?

Central Kansas Mental Health Center is a community mental health organization serving people in central Kansas. Organizations in this sector provide outpatient therapy, crisis support, case management, and related behavioral-health services. They routinely maintain clinical and administrative records so that care can be coordinated, billed, and documented under professional and legal obligations.

A breach involving such an organization is consequential because the records are not only identifiers used for mail or accounts. They can sit alongside sensitive context about mental health treatment, appointments, and communications with clinicians and staff. Even when a notice lists a very small number of affected people, the nature of the sector means any confirmed exposure of personal information deserves careful attention from those individuals and from the organization responsible for safeguarding the data.

The information in question

The breach notification, as reflected in the reported facts, names the exposed data as personal information. It does not itemize fields such as Social Security numbers, financial account details, clinical diagnoses, treatment notes, or insurance identifiers in the summary provided here. Exact contents beyond the label “personal information” are therefore unconfirmed in the public detail available from this filing.

Organizations of this kind typically hold demographic data, contact information, dates of birth, insurance or payment-related details, and clinical documentation needed for care. They may also hold government identifiers and emergency contacts. That is general sector practice, not a verified inventory of what was involved on September 21, 2025. Readers should treat only the notification’s stated category—personal information—and the count of two affected people as established by the disclosure, and treat any finer list of data elements as undisclosed unless a personal notice letter provides more.

Why it matters

For the two people named as affected, the real-world concern is misuse of personal information: targeted phishing that references a real provider relationship, attempts to open accounts, or social engineering that leans on details an outsider should not have. Mental health–related context, if any were present in the exposed material, can add privacy harm even when financial fraud does not follow. Because the public notice does not spell out every data element, affected individuals often have to rely on the letter they receive and on monitoring for unusual account or credit activity.

For the organization, a breach notice triggers legal notification duties, internal investigation, and often review of vendors, access controls, and patient-trust obligations. A small affected count does not remove those duties; it simply narrows the population that must be informed under the rules that applied to this filing. Public confidence in behavioral-health providers depends in part on how clearly and promptly people are told what is known and what is still uncertain.

If your data was in this breach

If you receive a notice from Central Kansas Mental Health Center, read it carefully for the date of the incident, the data types it lists for you, and any services the organization offers such as credit monitoring. Keep the letter. Consider placing fraud alerts with major credit bureaus if government identifiers or financial data are mentioned in your personal notice, and watch for unexpected bills, insurance changes, or messages that pressure you to “verify” care details. Use unique passwords on email and patient portals, and treat unsolicited calls or texts about the breach with skepticism unless you initiated contact through official channels.

You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data from other incidents, which helps you see whether the same address appears in unrelated dumps and whether you should tighten account security more broadly. If you were not contacted and have no reason to believe you were among the two people identified in the Indiana filing, your data may not have been involved; when in doubt, you may still ask the organization whether your records were part of the September 21, 2025 incident described in the June 24, 2026 report.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyCentral Kansas Mental Health Center security record
74/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Central Kansas Mental Health Center’s full breach history →

More recent breaches

AssuranceAmerica Managing General Agency LLC Data Breach Notice (Indiana Attorney General)July 10, 2026Travala Pte Ltd Data Breach Notice (Indiana Attorney General)July 5, 2026Graphic Information Systems Inc Data Breach Notice (Indiana Attorney General)June 30, 2026North Los Angeles County Regional Center Data Breach Notice (Indiana Attorney General)June 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Central Kansas Mental Health Center Data Breach Notice (Indiana Attorney General) →

Source: Indiana Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram