Devereux Foundation Data Breach: What You Need to Know

Devereux Foundation, a nonprofit healthcare and behavioral health organization, reported a data security incident with breach dates of November 6, 2025 and November 9, 2025. The notification was filed with the California Attorney General’s office, but the official PDF submitted with that filing is a scanned image, so no readable text could be extracted from it. That means we don’t yet know exactly how the incident occurred, whether it involved hacking, an internal error, a lost device, or something else, and we’re not able to state a specific cause here. We’ll update this page if a readable version of the notice becomes available.

Because the underlying document couldn’t be read, the filing does not indicate how many people were affected or whether the notice was sent to California residents specifically, employees, clients, patients, or another group. Devereux Foundation works in the healthcare and human services space, so anyone who has interacted with the organization as a client, patient, employee, or family member of a client may want to pay attention to any direct notification letter they receive, since that letter should contain the specific details this filing is missing.

What information was exposed?
  • The specific data types involved were not disclosed in the readable portion of this filing.
  • Healthcare-related breaches often involve some combination of names, contact information, Social Security numbers, medical record numbers, treatment information, or insurance details, but we cannot confirm which of these, if any, applied here.
  • If you receive a direct letter from Devereux Foundation, it should list exactly which of your personal details were involved — keep that letter for your records.

The filing does not mention any offer of free credit monitoring, identity protection services, or similar assistance from Devereux Foundation. If you received a letter directly from the organization, check it for any enrollment codes, website links, or deadlines related to a protective service offer, since that information would not appear in this regulatory filing.

What should you do now?
  • Watch your mail and email for a direct notification letter from Devereux Foundation, which should spell out exactly what information of yours was involved.
  • Review statements from any health insurers, medical providers, or financial institutions you use for unfamiliar charges, claims, or account activity.
  • Request a free copy of your credit report from each of the three major credit bureaus and look for any accounts or inquiries you don’t recognize.
  • Consider placing a fraud alert or credit freeze with the credit bureaus if you have reason to believe sensitive identifiers like your Social Security number may have been involved.
  • Be cautious of unexpected calls, texts, or emails referencing this incident, since scammers sometimes use breach news to impersonate companies — verify any contact by reaching Devereux Foundation through a number or website you look up independently, not one provided in a suspicious message.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere online or is being misused.
  • For a sense of how other healthcare organizations have handled similar incidents, you can read about the AgelessRx data breach notification and the steps affected individuals were advised to take.

Leave a Comment