The Center OC Data Breach Exposes Highly Sensitive Client Records
The Gay & Lesbian Community Services Center of Orange County, Inc., known as The Center OC, experienced a data security incident in late 2025. This breach exposed deeply personal client information, including sensitive health and financial records, raising serious privacy concerns for those affected. Such an event suggests potential failures in safeguarding confidential data, prompting individuals who received a notification letter to understand their rights and options.
Received a Gay & Lesbian Community Services Center of Orange County, Inc. notification letter? Find out in minutes if you qualify for compensation.
Free case review- State
- California
- Breach date
- December 25, 2025
- Reported
- June 5, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Contact Information
- Health Insurance ID Number
- Mental Health Counseling Records
- Diagnosis and Treatment Information
- Financial Assistance Records
The Gay & Lesbian Community Services Center of Orange County, Inc., also operating as The Center OC, reported a data security incident on June 5, 2026, stemming from an event on December 25, 2025. This organization provides critical health and social services to the LGBTQ+ community in Southern California, necessitating the collection and secure storage of highly personal and confidential client information. The breach underscores the constant threat non-profit and community health organizations face from cybercriminals.
The compromised data from The Center OC incident included, but was not limited to, individuals' Full Name, Date of Birth, Social Security Number, Contact Information, Health Insurance ID Number, Mental Health Counseling Records, Diagnosis and Treatment Information, and Financial Assistance Records. The exposure of such sensitive details is particularly alarming for LGBTQ+ individuals, as it can lead to targeted discrimination, harassment, and severe emotional distress.
The unauthorized disclosure of core identifiers like Social Security Numbers and specific health and financial information creates long-term risks. Affected individuals may face increased vulnerability to identity theft, medical fraud, unauthorized credit applications, and even tax refund fraud, issues that can persist for years and require significant time and effort to resolve.
Under California law, organizations entrusted with sensitive personal and health information have strict legal duties to implement and maintain reasonable security measures. This includes adherence to statutes like the California Confidentiality of Medical Information Act (CMIA) and general common-law duties of care. A data breach strongly suggests that these necessary technological safeguards may not have been adequately maintained to protect clients from preventable cyber threats.
If you received a data breach notification letter from The Center OC, it serves as formal acknowledgment that your private information was compromised due to inadequate security measures. This notification provides affected individuals with the legal standing necessary to participate in a class action lawsuit against the organization. Our firm handles these complex privacy and data breach cases on a contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf. We are currently monitoring the investigation into this incident.
Received the Gay & Lesbian Community Services Center of Orange County, Inc. notification letter? The Gay & Lesbian Community Services Center of Orange County, Inc. case file tracks this filing.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- ZZ Diag Probe
- Fragomen, Del Rey, Bernsen & Loewy, LLP
- Sheppard, Mullin, Richter & Hampton LLP
- Marana Health Center
- Lincoln Property Company Commercial LLC
- Aldrich Services LLP
- DriveWealth
- American Family Connect Insurance Company
- Nishiyamato Academy
- ProCamps
- Challenge Financial Services, Inc.
- San Bernardino County on behalf of Arrowhead Regional Medical Center
- Upbound Group, Inc.
- Financial Administrative Support Services