COMHAR Inc. Discloses Data Breach Impacting Sensitive Health and Personal Information
Philadelphia-based nonprofit COMHAR Inc., which provides behavioral health, intellectual disability, HIV/AIDS support, and home healthcare services, recently reported a data breach affecting an undisclosed number of individuals. The organization, founded in 1975, first acknowledged the incident in a public notice on September 4, 2026.
The breach came to light after the threat actor Worldleaks posted on the dark web on July 1, 2026, claiming to have stolen COMHAR’s data and threatening to release it within days. COMHAR detected unusual network activity shortly after and engaged third-party cybersecurity specialists to investigate. By July 17, 2026, the investigation confirmed that an unauthorized actor had copied files and folders on or before that date.
While the full scope of the breach remains under review, potentially exposed data includes personally identifiable information (PII) and protected health information (PHI), such as names, addresses, dates of birth, Social Security numbers, treatment notes, diagnoses, medications, and health insurance details.
COMHAR has begun notifying affected individuals and has established a dedicated helpline (1-888-941-5180) for inquiries, available Monday through Friday from 8 a.m. to 8 p.m. ET. Additional details can also be requested in writing at 100 W. Lehigh Ave., Philadelphia, PA 19133. The investigation into the breach’s full impact is ongoing.
Source: https://www.claimdepot.com/data-breach/comhar-2026
COMHAR, Inc. cybersecurity rating report: https://www.rankiteo.com/company/comhar-inc-
"id": "COM1788964486",
"linkid": "comhar-inc-",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Undisclosed',
'industry': 'Behavioral Health, Intellectual '
'Disability, HIV/AIDS Support, Home '
'Healthcare',
'location': 'Philadelphia, PA, USA',
'name': 'COMHAR Inc.',
'type': 'Nonprofit'}],
'attack_vector': 'Unknown (initial access via dark web threat actor claim)',
'customer_advisories': 'Helpline established (1-888-941-5180), written '
'request option available',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': ['Names',
'Addresses',
'Dates of birth',
'Social Security '
'numbers',
'Treatment notes',
'Diagnoses',
'Medications',
'Health insurance '
'details'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Protected health information '
'(PHI)']},
'date_detected': '2026-07-01',
'date_publicly_disclosed': '2026-09-04',
'description': 'Philadelphia-based nonprofit COMHAR Inc. disclosed a data '
'breach affecting an undisclosed number of individuals. The '
'breach involved unauthorized access to sensitive personally '
'identifiable information (PII) and protected health '
'information (PHI).',
'impact': {'data_compromised': 'Personally identifiable information (PII) and '
'protected health information (PHI)',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'motivation': 'Data exfiltration and potential extortion',
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'date_accessed': '2026-09-04',
'source': 'Public notice by COMHAR Inc.'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA (potential)']},
'response': {'communication_strategy': 'Public notice, dedicated helpline, '
'written request option',
'containment_measures': 'Investigation and confirmation of '
'unauthorized access',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Notification of affected individuals, '
'establishment of a helpline',
'third_party_assistance': 'Yes (cybersecurity specialists)'},
'threat_actor': 'Worldleaks',
'title': 'COMHAR Inc. Data Breach Impacting Sensitive Health and Personal '
'Information',
'type': 'Data Breach'}