2025 Gay & Lesbian Community Services Center of Orange County — network intrusion; up to 75,532 individuals
Data compromised
Names, DOB, SSNs, diagnosis/prescription/medical history/treatment, MRNs, health insurance, driver’s license/gov IDs/passport/TIN, financial account and payment card info, biometric identifiers (varied by person)
Technical writeup
Verified nonprofit healthcare disclosure — HIPAA Journal coverage July 13, 2026 (CA AG listing reported 2026-06-05). Gay & Lesbian Community Services Center of Orange County identified suspicious network activity on or around December 26, 2025. Forensics confirmed unauthorized access December 25–26, 2025; files containing sensitive information may have been viewed or acquired. Data review completed May 6, 2026. Up to 75,532 individuals may have been affected. Compromised network areas held full names, dates of birth, Social Security numbers, diagnosis/prescription/medical history and treatment information, medical record numbers, health insurance information, driver’s license and other government/state/passport/taxpayer IDs, financial account and payment card information, and biometric identifiers (types varied by individual). The website notice advised vigilance but did not mention complimentary credit monitoring. BreachHistory updates recordsAffected to the attested up-to 75,532 figure.
Root cause
Unauthorized network access Dec 25–26, 2025; files may have been viewed or acquired