DataBreachCaseFile.com
Investigation OpenMassachusetts AG filing · December 16, 2025

Evoke Wellness at Hilliard Reports Data Security Incident to Massachusetts AG

OCAT, LLC, operating as Evoke Wellness at Hilliard, filed a data breach report with the Massachusetts Attorney General on December 16, 2025. This incident indicates that personal information handled by the behavioral health facility may have been exposed, prompting individuals to take protective measures.

State
Massachusetts
Reported
December 16, 2025

OCAT, LLC, doing business as Evoke Wellness at Hilliard, a behavioral health and addiction treatment facility, has reported a data security incident to the Massachusetts Attorney General's office. The filing date for this incident was December 16, 2025, and the investigation into the compromise is currently ongoing.

The official source indicates that the incident involved a breakdown in administrative and technical safeguards at the facility. While the specific nature of the breach and the exact types of information involved have not been detailed in the public filing, such incidents often involve unauthorized access to systems containing sensitive personal data.

For individuals whose personal information may have been exposed, this situation carries potential risks. The exposure of sensitive data, even if general in nature, can lead to various forms of misuse. It is important for affected individuals to understand that such incidents, as reported in public filings, signify a potential compromise of their private data.

Given the unspecified nature of the exposed information, individuals should remain vigilant. General protective steps include carefully reviewing statements from financial institutions and healthcare providers for any unusual activity. It is also advisable to monitor credit reports for unauthorized accounts or suspicious inquiries.

While the investigation into the Evoke Wellness at Hilliard incident is ongoing, those who receive direct notification should carefully review the communication for any specific guidance provided by the organization. Taking proactive measures can help mitigate potential risks associated with the exposure of personal information.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases