Lifeways Inc. Discloses Data Breach Impacting Sensitive Health and Personal Information
Lifeways Inc., a nonprofit behavioral health provider serving Eastern Oregon and parts of Idaho, reported a data security incident involving unauthorized access to employee email accounts. The breach was first detected on January 21, 2026, when suspicious activity was identified in an employee’s email. The organization immediately secured its systems and launched an investigation with third-party cybersecurity specialists.
The forensic review concluded that unauthorized parties accessed emails containing sensitive data. By May 8, 2026, investigators confirmed the exposure of personally identifiable information (PII) and protected health information (PHI). Compromised data included:
- PII: Names, dates of birth, Social Security numbers, driver’s license/state ID numbers, and financial account details.
- PHI: Medical record numbers, diagnoses, treatment details, prescription information, provider names, and insurance identifiers (Medicare, Medicaid, and group account numbers).
Lifeways publicly disclosed the incident on June 11, 2026, though the total number of affected individuals remains undisclosed. The organization has set up a dedicated call center (1-800-405-6108) for impacted individuals to seek assistance. No evidence of fraudulent misuse of the exposed data has been reported.
Source: https://www.claimdepot.com/data-breach/lifeways-2026
Community Counseling Solutions cybersecurity rating report: https://www.rankiteo.com/company/community-counseling-solutions
"id": "COM1784760336",
"linkid": "community-counseling-solutions",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Behavioral Health',
'location': 'Eastern Oregon and parts of Idaho',
'name': 'Lifeways Inc.',
'type': 'Nonprofit'}],
'attack_vector': 'Unauthorized access to employee email accounts',
'customer_advisories': 'Dedicated call center (1-800-405-6108) for impacted '
'individuals',
'data_breach': {'personally_identifiable_information': ['Names',
'Dates of birth',
'Social Security '
'numbers',
'Driver’s '
'license/state ID '
'numbers',
'Financial account '
'details',
'Medical record '
'numbers',
'Diagnoses',
'Treatment details',
'Prescription '
'information',
'Provider names',
'Insurance '
'identifiers '
'(Medicare, Medicaid, '
'and group account '
'numbers)'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Protected health information '
'(PHI)']},
'date_detected': '2026-01-21',
'date_publicly_disclosed': '2026-06-11',
'description': 'Lifeways Inc., a nonprofit behavioral health provider, '
'reported a data security incident involving unauthorized '
'access to employee email accounts. The breach exposed '
'personally identifiable information (PII) and protected '
'health information (PHI).',
'impact': {'data_compromised': 'Personally identifiable information (PII) and '
'protected health information (PHI)',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'Employee email accounts'},
'investigation_status': 'Concluded',
'references': [{'source': 'Public disclosure by Lifeways Inc.'}],
'response': {'communication_strategy': 'Public disclosure and dedicated call '
'center',
'containment_measures': 'Secured systems and launched '
'investigation',
'incident_response_plan_activated': 'Yes',
'third_party_assistance': 'Cybersecurity specialists'},
'title': 'Lifeways Inc. Data Breach Impacting Sensitive Health and Personal '
'Information',
'type': 'Data Breach'}