Cook Counseling Allegedly Breached, 7,670 Mental Health Patient Records Exposed

A threat actor claims to have stolen 111 GB of Cook Counseling patient records, including psychotherapy notes, diagnoses, insurance information and identification documents.
Screenshot of a forum post claiming a Cook Counseling and Consulting EHR breach affecting 7,670 patients and 111 GB of data.
A threat actor claims to have stolen 111 GB of data from Cook Counseling and Consulting, including thousands of patient records and psychotherapy notes. Sensitive patient information shown in the original post has been redacted by BreachNews.

A threat actor claims to have stolen the electronic health record database of Cook Counseling and Consulting, an Ohio mental health practice, allegedly exposing 111 GB of highly sensitive patient information, including psychotherapy notes, psychiatric evaluations, diagnoses, treatment plans, insurance records and identification documents.

The alleged breach involves records associated with 7,670 patients and 23,647 clinical notes documenting private mental health treatment. The attacker claims the stolen information covers September 2022 through September 2026, potentially spanning much of the practice’s operating history.

The dataset was advertised on October 10, 2026, alongside descriptions and purported examples of confidential patient records. BreachNews is withholding all patient identities and details contained in the alleged clinical records.

The threat actor also claims to have compromised 2 accounts within the clinic’s electronic health record system. According to the account, Cook Counseling blocked an initial attempt to export data, but the attacker subsequently used another compromised account to retrieve the database.

These claims have not been independently verified. Cook Counseling and Consulting had not issued any public statement addressing the alleged breach at the time of publication.

Psychotherapy notes and patient documents allegedly exposed

The most concerning aspect of the alleged compromise is the sensitivity of the information reportedly obtained. Electronic health records maintained by mental health providers can contain detailed accounts of patients’ psychological conditions, treatment histories, traumatic experiences and other deeply private information.

The attacker claims the dataset contains 23,647 full-text clinical notes associated with approximately 3,210 clients, including psychotherapy and progress notes, intake records, EMDR documentation, psychiatric evaluations and other clinical assessments.

The alleged dataset also includes:

  • Patient records: 7,670 unique clients.
  • Total data: 111 GB comprising 56,347 files.
  • Clinical notes: 23,647 records involving approximately 3,210 clients.
  • Treatment plans: 3,206.
  • Client documents: 30,072, including 28,546 PDFs and scans.
  • Appointments: 57,307.
  • Invoices: 47,465.
  • Insurance claims: 28,207.
  • Payment records: 25,202.
  • Insurance identifiers: 4,573 entries.
  • Contact information: Thousands of alleged addresses, phone numbers and email addresses.

The attacker claims the patient documents include photo identification, insurance cards, psychological evaluations and clinical correspondence. The figures originate entirely from the threat actor and should not be interpreted as confirmed exposure totals.

Some of the purported records shown as evidence contained exceptionally sensitive mental health information. BreachNews has excluded those details, along with patient names, contact information, insurance identifiers and other personally identifiable information.

Second account allegedly used after initial access was blocked

The attacker claims the clinic’s electronic health record system was initially accessed through an account that did not have multifactor authentication enabled.

According to the claim, an attempt to extract information using the platform’s built-in export functionality was blocked after Cook Counseling took action. The attacker alleges that a second compromised account remained accessible and was subsequently used to retrieve the patient database.

If accurate, the sequence could indicate that multiple accounts were compromised before or during the organization’s response. However, there is currently no independent evidence confirming the claimed authentication weakness, the number of compromised accounts or the method used to extract the information.

The electronic health record platform involved has not been publicly identified, and BreachNews has not established whether the alleged compromise affected Cook Counseling’s own infrastructure or access to a third-party service.

Four years of records allegedly affected

The threat actor claims the stolen information spans September 2022 through September 2026 and includes both current and former patients.

The attacker describes 4,237 patient records as active, 2,148 as archived and 1,167 as inactive. Those categories total 7,552 records, 118 fewer than the claimed 7,670 unique patients. The discrepancy has not been explained.

The alleged dataset also includes billing and insurance information. The attacker claims to possess thousands of insurance member identifiers, payment records and claims, as well as billing exports recording approximately $3.73 million in gross revenue. That figure appears to describe financial activity contained in the alleged records rather than money stolen during the incident.

If authentic, the combination of clinical records, identification documents, insurance information and contact details could create risks ranging from identity and insurance fraud to highly targeted phishing and impersonation attempts.

Cook Counseling operates across central Ohio

Cook Counseling and Consulting provides mental health services in Columbus and surrounding communities. Its services include psychotherapy, psychiatric care, EMDR therapy, medication management and counseling for children, teenagers and adults.

Cook Counseling’s official website currently advertises more than 40 licensed professionals across 6 locations in central Ohio.

The attacker claims the stolen records reference 116 clinicians across 20 office locations. That difference could reflect historical providers or locations, internal administrative records or inaccuracies in the attacker’s figures.

Mental health data carries lasting privacy risks

The alleged exposure is particularly serious because psychotherapy records can contain information that cannot be replaced or reset like a password or payment card.

Clinical notes may document diagnoses, symptoms, trauma, family circumstances, treatment history and other information disclosed privately to healthcare professionals. Unauthorized disclosure could expose patients to harassment, discrimination, fraud or attempts to exploit their medical history.

The attacker also claims attempts were made to negotiate with Cook Counseling before the information was advertised. There is no independent confirmation that the clinic received an extortion demand, entered negotiations or refused payment.

HIPAA reporting could follow if breach is confirmed

If an investigation determines that protected health information was accessed or disclosed without authorization, the incident could trigger notification requirements under the Health Insurance Portability and Accountability Act.

Breaches involving 500 or more individuals generally must be reported to the U.S. Department of Health and Human Services within the applicable reporting period, in addition to notification requirements for affected individuals.

BreachNews tracks incidents published through the HHS Office for Civil Rights breach portal in its HIPAA Breach Tracker, which provides a searchable feed of healthcare breaches affecting 500 or more individuals.

Cook Counseling does not currently appear in the tracker in connection with this alleged incident. Its absence does not indicate whether a breach occurred, as reporting obligations and deadlines depend on the findings and timing of an organization’s investigation.

Cook Counseling and Consulting had not issued any public statement addressing the allegations at the time of publication. Until the organization or regulators disclose additional information, the claimed 7,670-patient impact, 111 GB data theft and account compromise remain allegations attributed to the threat actor.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →