Operation PAR, Boley Centers, and Eleos Health Report Data Breach Affecting Florida Patients and Employees
On June 10, 2025, Florida-based behavioral health providers Operation PAR and Boley Centers, alongside digital health company Eleos, detected unauthorized network access. A subsequent investigation, supported by cybersecurity experts, revealed that sensitive files may have been accessed or exfiltrated between June 6 and June 10, 2025.
The exposed data potentially includes names, Social Security numbers, medical records, and driver’s license information belonging to patients and employees. The organizations have begun notifying affected individuals, though the full scope of the breach remains under review.
Legal teams are now examining the incident to determine whether a class action lawsuit can be filed on behalf of those impacted, citing potential harm such as loss of privacy, financial costs, and time spent mitigating the breach. The investigation is ongoing, with attorneys seeking input from individuals who received breach notifications or believe their data was compromised.
This incident highlights the growing cybersecurity risks faced by healthcare providers handling sensitive patient information. No further details on the attack vector or threat actors have been disclosed.
Source: https://www.classaction.org/data-breach-lawsuits/operation-par-boley-centers-and-eleos-july-2026
Operation PAR, Inc. cybersecurity rating report: https://www.rankiteo.com/company/operation-par
Eleos Health cybersecurity rating report: https://www.rankiteo.com/company/eleoshealth
"id": "OPEELE1782966380",
"linkid": "operation-par, eleoshealth",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients and employees',
'industry': 'Healthcare',
'location': 'Florida, USA',
'name': 'Operation PAR',
'type': 'Behavioral Health Provider'},
{'customers_affected': 'Patients and employees',
'industry': 'Healthcare',
'location': 'Florida, USA',
'name': 'Boley Centers',
'type': 'Behavioral Health Provider'},
{'customers_affected': 'Patients and employees',
'industry': 'Healthcare',
'name': 'Eleos Health',
'type': 'Digital Health Company'}],
'customer_advisories': 'Notifying affected individuals',
'data_breach': {'data_exfiltration': 'Potential',
'personally_identifiable_information': 'Names, Social '
'Security numbers, '
'driver’s license '
'information',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personally Identifiable '
'Information, Medical Records'},
'date_detected': '2025-06-10',
'description': 'Florida-based behavioral health providers Operation PAR and '
'Boley Centers, alongside digital health company Eleos, '
'detected unauthorized network access. A subsequent '
'investigation revealed that sensitive files may have been '
'accessed or exfiltrated between June 6 and June 10, 2025. The '
'exposed data potentially includes names, Social Security '
'numbers, medical records, and driver’s license information '
'belonging to patients and employees.',
'impact': {'data_compromised': 'Names, Social Security numbers, medical '
'records, driver’s license information',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential class action lawsuit'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Growing cybersecurity risks faced by healthcare providers '
'handling sensitive patient information',
'regulatory_compliance': {'legal_actions': 'Potential class action lawsuit'},
'response': {'communication_strategy': 'Notifying affected individuals',
'third_party_assistance': 'Cybersecurity experts'},
'title': 'Operation PAR, Boley Centers, and Eleos Health Data Breach',
'type': 'Data Breach'}