Company Details
richmond-behavioral-health-authority
513
3,093
62
rbha.org
0
RIC_1167743
In-progress


Richmond Behavioral Health Company CyberSecurity Posture
rbha.orgRichmond Behavioral Health (RBH) fearlessly champions the health, wellness, and recovery of individuals and families in our community. Richmond Behavioral Health Authority (RBHA), a community health agency, is committed to bringing essential care to the people we serve through crisis intervention, mental health services, developmental support, and substance use prevention and treatment. Richmond Behavioral Health Foundation (RBHF), a nonprofit 501(c)(3) organization, supports RBH’s mission through community awareness initiatives, fundraising, and community partnerships. As a united force, RBH takes a proactive, innovative approach to activating the transformative power of behavioral health. Our vision is to create an inclusive, healthy community where individuals have the courage to believe in a better tomorrow and are inspired to reach their highest potential. Richmond Behavioral Health Authority (RBHA) is licensed by the Virginia Department of Behavioral Health and Developmental Services. Our social media pages are intended for informational and educational purpose only. We are unable to respond to requests for contact related to services or treatment at RBHA.
Company Details
richmond-behavioral-health-authority
513
3,093
62
rbha.org
0
RIC_1167743
In-progress
Between 600 and 649

RBH Global Score (TPRM)XXXX

Description: RBHA Hit by Ransomware Attack, Exposing Sensitive Data of Over 113,000 Individuals On September 29, 2025, Richmond Behavioral Health Authority (RBHA) suffered a ransomware attack that compromised the personally identifiable information (PII) and protected health information (PHI) of at least 113,232 individuals across the U.S. Malicious actors breached RBHA’s network, deploying ransomware that encrypted portions of the organization’s systems. The intrusion was detected and contained the following day, September 30. While RBHA found no definitive evidence that the exposed data was accessed or misused, the organization could not rule out the possibility, prompting notifications to affected individuals as a precaution. The breach exposed highly sensitive details, including full names, Social Security numbers, passport numbers, financial account information, and medical records. This combination of data heightens the risk of identity theft and fraud for those impacted. RBHA reported the incident to the U.S. Department of Health and Human Services on November 28, 2025, and published a Notice of Data Breach on its website. Affected individuals were notified by mail. In response, RBHA engaged internal IT teams and third-party cybersecurity experts to investigate the breach, secure its systems, and prevent further compromise. The organization has also set up a dedicated hotline (844-572-2716) for impacted individuals seeking assistance.


No incidents recorded for Richmond Behavioral Health in 2026.
No incidents recorded for Richmond Behavioral Health in 2026.
No incidents recorded for Richmond Behavioral Health in 2026.
RBH cyber incidents detection timeline including parent company and subsidiaries

Richmond Behavioral Health (RBH) fearlessly champions the health, wellness, and recovery of individuals and families in our community. Richmond Behavioral Health Authority (RBHA), a community health agency, is committed to bringing essential care to the people we serve through crisis intervention, mental health services, developmental support, and substance use prevention and treatment. Richmond Behavioral Health Foundation (RBHF), a nonprofit 501(c)(3) organization, supports RBH’s mission through community awareness initiatives, fundraising, and community partnerships. As a united force, RBH takes a proactive, innovative approach to activating the transformative power of behavioral health. Our vision is to create an inclusive, healthy community where individuals have the courage to believe in a better tomorrow and are inspired to reach their highest potential. Richmond Behavioral Health Authority (RBHA) is licensed by the Virginia Department of Behavioral Health and Developmental Services. Our social media pages are intended for informational and educational purpose only. We are unable to respond to requests for contact related to services or treatment at RBHA.


The Cigna Group is a global health company committed to creating a better future built on the vitality of every individual and every community. We relentlessly challenge ourselves to partner and innovate solutions for better health. The Cigna Group includes products and services marketed under Cig
Cleveland Clinic, located in Cleveland, Ohio, is a not-for-profit, multispecialty academic medical center that integrates clinical and hospital care with research and education. Founded in 1921 by four renowned physicians with a vision of providing outstanding patient care based upon the principles

Ramsay Health Care is a trusted provider of private hospital and healthcare services in Australia, Europe and the United Kingdom. Every year, millions of patients put their trust in Ramsay, confident in our ability to deliver safe, high-quality healthcare with outstanding clinical outcomes. We ope

Lehigh Valley Health Network, part of Jefferson Health, is proud to be part of a leading integrated academic health care delivery system. Together, we’re among the top 15 not-for-profit health systems in the U.S., with 65,000 colleagues, 32 hospitals and more than 700 sites of care across eastern P

AP-HP (Greater Paris University Hospitals) is a European world-renowned university hospital. Its 39 hospitals treat 8 million people every year: in consultation, emergency, during scheduled or home hospitalizations. The AP-HP provides a public health service for everyone, 24 hours a day. This missi
Siemens Healthineers is a leading medtech company with over 125 years of experience. We pioneer breakthroughs in healthcare. For everyone. Everywhere. Sustainably. Our portfolio, spanning in vitro and in vivo diagnostics to image-guided therapy and cancer care, is crucial for clinical decision-makin
The University of Texas MD Anderson Cancer Center is one of the world's most respected centers devoted exclusively to cancer patient care, research, education and prevention. MD Anderson provides cancer care at several convenient locations throughout the Greater Houston Area and collaborates with co
Committed to Life - We save and improve human lives with affordable, accessible, and innovative healthcare products and the highest quality in clinical care. Fresenius is a global healthcare company headquartered in Bad Homburg v. d. Höhe, Germany. In fiscal year 2024, Fresenius generated €21.5 bil

Fueled by our bold purpose to improve the health of humanity, we are transforming from a traditional health benefits organization into a lifetime trusted health partner. Our nearly 100,000 associates serve more than 118 million people, at every stage of health. We address a full range of needs wi
.png)
Hackers have targeted a nonprofit mental health services provider in a cybersecurity incident that may have exposed sensitive personal...
Richmond Behavioral Health Authority (RBHA), the public entity responsible for providing mental health, substance abuse, and prevention...
PITTSBURGH, Pa., Dec. 18, 2025 (GLOBE NEWSWIRE) -- Richmond Behavioral Health Authority (“RBHA”),1 recently announced a cybersecurity...
A ransomware group stole the personal information of over 113000 people from Richmond Behavioral Health Authority's network.
Data breach at RBHA affected 113232 people, exposing names, SSNs, medical info, and more. Check your accounts and monitor credit.
Through a ransomware attack, personal and health-related information of an unknown number of Richmond Behavioral Health Authority (RBHA)...
Qilin ransomware group has claimed compromising more organizations this week, making October among its most productive months as a...
Resecurity's new report details how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
The following Resecurity report will explore the Qilin ransomware-as-a-service (RaaS) operation's reliance on bullet-proof-hosting (BPH)...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Richmond Behavioral Health is http://www.rbha.org.
According to Rankiteo, Richmond Behavioral Health’s AI-generated cybersecurity score is 636, reflecting their Poor security posture.
According to Rankiteo, Richmond Behavioral Health currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Richmond Behavioral Health has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Richmond Behavioral Health is not certified under SOC 2 Type 1.
According to Rankiteo, Richmond Behavioral Health does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Richmond Behavioral Health is not listed as GDPR compliant.
According to Rankiteo, Richmond Behavioral Health does not currently maintain PCI DSS compliance.
According to Rankiteo, Richmond Behavioral Health is not compliant with HIPAA regulations.
According to Rankiteo,Richmond Behavioral Health is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Richmond Behavioral Health operates primarily in the Hospitals and Health Care industry.
Richmond Behavioral Health employs approximately 513 people worldwide.
Richmond Behavioral Health presently has no subsidiaries across any sectors.
Richmond Behavioral Health’s official LinkedIn profile has approximately 3,093 followers.
Richmond Behavioral Health is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
Yes, Richmond Behavioral Health has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/richmond-behavioral-health-authority.
Yes, Richmond Behavioral Health maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/richmond-behavioral-health-authority.
As of January 25, 2026, Rankiteo reports that Richmond Behavioral Health has experienced 1 cybersecurity incidents.
Richmond Behavioral Health has an estimated 31,618 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and third party assistance with yes (cybersecurity experts), and containment measures with terminated unauthorized access, and remediation measures with secured personal information and protected network from further compromise, and communication strategy with notice of data breach on website, mailed notifications to affected individuals..
Title: Richmond Behavioral Health Authority (RBHA) Data Security Incident
Description: Richmond Behavioral Health Authority (RBHA) experienced a significant data security incident that exposed personally identifiable information (PII) and protected health information (PHI) of at least 113,232 individuals in the United States. Malicious actors gained unauthorized access to RBHA’s network and deployed ransomware, encrypting portions of the organization’s systems.
Date Detected: 2025-09-30
Date Publicly Disclosed: 2025-11-28
Type: Ransomware Attack
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Personally identifiable information (PII) and protected health information (PHI)
Systems Affected: Portions of RBHA’s network
Identity Theft Risk: High
Payment Information Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Protected Health Information (Phi) and .

Entity Name: Richmond Behavioral Health Authority (RBHA)
Entity Type: Healthcare Provider
Industry: Healthcare
Location: United States
Customers Affected: 113,232

Incident Response Plan Activated: Yes
Third Party Assistance: Yes (cybersecurity experts)
Containment Measures: Terminated unauthorized access
Remediation Measures: Secured personal information and protected network from further compromise
Communication Strategy: Notice of Data Breach on website, mailed notifications to affected individuals
Incident Response Plan: The company's incident response plan is described as Yes.
Third-Party Assistance: The company involves third-party assistance in incident response through Yes (cybersecurity experts).

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi)
Number of Records Exposed: 113,232
Sensitivity of Data: High
Data Encryption: Yes (ransomware encryption)
Personally Identifiable Information: Full nameSocial Security numberPassport numberFinancial account informationMedical information
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Secured personal information and protected network from further compromise.
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by terminated unauthorized access.

Data Encryption: Yes

Regulations Violated: HIPAA,
Regulatory Notifications: Reported to U.S. Department of Health and Human Services

Recommendations: Monitor bank and credit card accounts for unauthorized transactions, Obtain and review free credit reports from major credit bureaus, Consider placing a fraud alert or credit freeze on credit files, Watch for suspicious emails, phone calls, or mail related to the breachMonitor bank and credit card accounts for unauthorized transactions, Obtain and review free credit reports from major credit bureaus, Consider placing a fraud alert or credit freeze on credit files, Watch for suspicious emails, phone calls, or mail related to the breachMonitor bank and credit card accounts for unauthorized transactions, Obtain and review free credit reports from major credit bureaus, Consider placing a fraud alert or credit freeze on credit files, Watch for suspicious emails, phone calls, or mail related to the breachMonitor bank and credit card accounts for unauthorized transactions, Obtain and review free credit reports from major credit bureaus, Consider placing a fraud alert or credit freeze on credit files, Watch for suspicious emails, phone calls, or mail related to the breach

Source: RBHA Notice of Data Breach
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: RBHA Notice of Data Breach.

Investigation Status: Ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notice of Data Breach on website and mailed notifications to affected individuals.

Customer Advisories: Dedicated toll-free hotline (844-572-2716) for affected individuals
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Dedicated toll-free hotline (844-572-2716) for affected individuals.
Most Recent Incident Detected: The most recent incident detected was on 2025-09-30.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-11-28.
Most Significant Data Compromised: The most significant data compromised in an incident was Personally identifiable information (PII) and protected health information (PHI).
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Terminated unauthorized access.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Personally identifiable information (PII) and protected health information (PHI).
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 113.2K.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Monitor bank and credit card accounts for unauthorized transactions, Obtain and review free credit reports from major credit bureaus, Consider placing a fraud alert or credit freeze on credit files, Watch for suspicious emails, phone calls and or mail related to the breach.
Most Recent Source: The most recent source of information about an incident is RBHA Notice of Data Breach.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Customer Advisory: The most recent customer advisory issued was an Dedicated toll-free hotline (844-572-2716) for affected individuals.
.png)
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.