CSIDB logo
Incident

Kern Psychiatric Health and Wellness Center

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 12:16

Linked entities

Victim
Kern Psychiatric Health and Wellness Center
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Pending
Resolved
Pending

Summary

A Bakersfield, California-based psychiatric and behavioral care provider experienced a data breach through its management company, which detected suspicious activity on its network and confirmed unauthorized access by a third party. The compromised parts of the network contained personal and protected health information of patients, including names, dates of birth, Social Security numbers, medical record numbers, driver's license numbers, government-issued ID numbers, Medicare/Medicaid numbers, diagnoses, treatment information, lab results, patient account numbers, provider names and locations, and health insurance information. Notification letters were mailed to affected individuals, and complimentary credit monitoring and identity theft protection services were offered for 12 months. The exact number of affected individuals has not been publicly disclosed, as the incident had not yet appeared on the HHS' Office for Civil Rights breach portal at the time of reporting.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Kern Psychiatric Health and Wellness Center, a psychiatric and behavioral care provider based in Bakersfield, California, experienced a data security incident through its management company, Genesis Healthcare Management. On June 22, 2026, Genesis Healthcare Management identified suspicious activity within its computer network. The management company engaged third-party cybersecurity specialists to assist with an investigation, which confirmed that the network had been accessed by an unauthorized third party. The compromised segments of the network contained the personal and protected health information of Kern Psychiatric Health and Wellness Center patients.

The data exposed in the breach included a broad range of personal and medical information. Specifically, the compromised records contained names, dates of birth, Social Security numbers, medical record numbers, driver's license numbers, government-issued ID numbers, and Medicare/Medicaid numbers. Additionally, clinical information was involved, including diagnoses, treatment information, and lab results. Other affected data elements included patient account numbers, provider names and locations, and health insurance information. The incident has been reported to the California Attorney General, indicating compliance with state-level notification requirements. Kern Psychiatric Health and Wellness Center began mailing notification letters to the affected individuals.

In response to the incident, Kern Psychiatric Health and Wellness Center, through Genesis Healthcare Management, is offering affected individuals complimentary credit monitoring and identity theft protection services for a period of 12 months. Notification letters are being sent to inform patients about the nature of the breach and the specific data elements that were compromised for each individual. As of the date of the article's publication, the incident had not yet appeared on the U.S. Department of Health and Human Services' Office for Civil Rights breach portal, leaving the total number of affected individuals undisclosed.

Sources

Sources available to members: 1 source.

CSIDB