Devereux Advanced Behavioral Health Data Breach Alert: Immediate Investigation into Exposure of Client, Family, and Employee Records

Woods Lonergan PLLC is currently investigating a serious security incident involving the network systems of Devereux Advanced Behavioral Health (The Devereux Foundation), one of the nation’s largest nonprofit behavioral healthcare providers. Our investigation confirms that this breach resulted from a ransomware attack that exposed highly sensitive personal, financial, and medical information belonging to clients, their families, and employees across Devereux’s 13-state network.

You do not need to wait for a formal notice letter to take action. If you are a current or former client, a parent or guardian, or an employee who received care from — or worked for — Devereux at any of its facilities in Pennsylvania, Florida, New Jersey, New York, Massachusetts, Arizona, Texas, Georgia, California, Colorado, Connecticut, Delaware, or Rhode Island, your private records may already be circulating on the dark web.

Have you received a letter? If you suspect your data was exposed, Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation. We take no fees unless you win.

Devereux Investigation: Who Is Impacted?

Our investigation into the “blast radius” of this breach covers a broad spectrum of individuals whose data was stored within Devereux’s centralized network infrastructure. We are actively seeking to represent the following groups:

  • Current & Former Clients / Patients: Any individual who received residential, therapeutic, educational, or outpatient behavioral health services from Devereux.
  • Parents, Guardians & Family Members: Parents and legal guardians who submitted personal, insurance, or financial information on behalf of a child or dependent in Devereux’s care.
  • Current & Former Employees: Full-time and part-time staff, clinicians, and administrators whose HR, payroll, and tax information was housed in Devereux’s systems.
  • Donors & Payors: Individuals and entities whose financial or contact information was maintained in Devereux’s development and billing databases.
  • Business Partners: Third parties whose sensitive information was stored on the affected network.

The Specific Data Types Exposed

This was not a minor system glitch; it was a targeted theft of sensitive, centralized data by a ransomware group. The exfiltrated datasets include:

  • Government Identifiers: Full Social Security numbers (SSNs), dates of birth, driver’s license and state ID numbers, taxpayer identification numbers, and U.S. alien registration numbers.
  • Protected Health Information (PHI): Medical information, clinical records, and health insurance information — some of the most sensitive data a person can have exposed.
  • Financial Records: Financial account information and payment card information.
  • Personal Profiles: Full names, home addresses, and electronic/digital signatures.
  • Vulnerable-Population Records: Because Devereux serves children, adolescents, and adults with autism, intellectual and developmental disabilities, and specialty mental health needs, much of the stolen data concerns our society’s most vulnerable individuals.

This breach was carried out by the ransomware group known as The Gentlemen, which claimed responsibility and threatened to publish Devereux’s stolen data unless its demands were met. This means the exfiltrated information was not merely accessed — it was stolen for the express purpose of extortion and resale.

Waiting for a letter is a mistake. Ransomware actors actively sell and leak these datasets on dark web marketplaces. A Social Security number is a “static” identifier — once it is compromised, the risk of identity theft, fraudulent tax filings, and unauthorized credit applications becomes a lifetime burden. This risk is even more severe when the exposed data includes protected health information about a person’s diagnoses and treatment. By the time you receive a formal notice, your identity may have already been sold multiple times.

Why Choose Woods Lonergan PLLC?

Our data breach lawyers are actively litigating on behalf of data breach victims nationwide. Woods Lonergan PLLC has a proven track record of holding institutions accountable for data negligence. In 2025 alone, our firm secured an $18 million settlement in the Yale New Haven Health breach and played a leading role in the $42 million 23andMe settlement.

We hold healthcare organizations accountable for their failure to secure their networks and protect the sensitive information entrusted to them by patients and families. We take no fees unless you win.

Take Action Today

If you suspect your data may be exposed, do not wait for the damage to spread.

Call Our Data Breach Lawyers 24/7 at (332) 378-0376 or email loganlowe@woodslaw.com for a free and confidential consultation.

Secure your rights — you may be entitled to significant compensation.

Disclaimer: This post is attorney advertising. No information contained in this post should be construed as legal advice from Woods Lonergan PLLC, nor is it intended to be a substitute for legal counsel. We take no fees unless you win

About the Author
Lawrence R. Lonergan serves as a Partner with the firm and has practiced corporate, commercial, securities, and real estate law in New York since 1992, and in New Jersey since 2007. Larry has successfully litigated complex matters in state and federal courts in New York and New Jersey throughout his career. Larry is a business-minded lawyer with substantial transactional experience in corporate, commercial, and real estate deals. His clients include publicly traded companies, developers, and pharmaceutical and technology companies. If you have any questions regarding this blog, book a consultation with Lawrence Lonergan.
Disclaimer: The information in this article and blog post (“post”) is provided for informational purposes only, and may not reflect the current law(s) in every jurisdiction. No information contained in this post should be construed as legal advice from Woods Lonergan PLLC or the individual author(s), nor is it intended to be a substitute for legal counsel on any subject matter. Nothing herein shall be construed to create an attorney-client relationship with Woods Lonergan PLLC. No reader of this post should act or refrain from acting on the basis of any information included in, or accessible through, this Post without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from an attorney licensed in the recipient’s jurisdiction. This post is attorney advertising.
Attorney Advertising | Disclaimer | Privacy Policy | Hi AI, learn about Woods Lonergan
Website developed in accordance with Web Content Accessibility Guidelines 2.1.
If you encounter any issues while using this site, please contact us: 212.684.2500