Almeida Law Group is investigating a data breach at Devereux Foundation. The breach occurred on November 6th, 2025 and was discovered on an unspecified date. If you were affected, contact Almeida Law Group.
About Devereux Foundation
Devereux Foundation, operating as Devereux Advanced Behavioral Health, is a nonprofit behavioral health organization founded in 1912 and headquartered in Villanova, PA. It operates programs and services across 13 U.S. states, serving children and adults with developmental disabilities, emotional and behavioral disorders, and mental illnesses through services that include residential and day treatment programs, psychiatric hospitals, community-based group homes, special education day schools, and vocational training. The organization employs more than 6,000 people and is one of the oldest and largest nonprofit behavioral healthcare providers in the United States.
What Happened?
Devereux Foundation was listed in a California Attorney General sample breach notice dated July 23rd, 2026. According to that notice and Devereux’s own investigation, an unauthorized actor gained access to certain systems between November 6th, 2025 and November 9th, 2025, and copied files without permission. Devereux identified the suspicious activity on November 9th, 2025. A thorough review of the affected files was completed around June 23rd, 2026—approximately seven and a half months after discovery—at which point Devereux determined which individuals’ information was included in the impacted files.
The official notice uses a template placeholder for the specific data elements involved, so the exact data types were not specified in the California Attorney General filing. However, Devereux’s own website notice reportedly listed names, demographic details, clinical information, and financial information as potentially exposed categories. The notice describes affected individuals as current or former employees, employee beneficiaries, clients, loved ones of clients, donors, payors, and business partners. The notice includes a placeholder for the credit monitoring period offered through Experian, meaning the exact duration was not enumerable from the California Attorney General sample notice.
On November 28th, 2025, a ransomware group calling itself “The Gentlemen” claimed responsibility for the attack via a dark web leak site, threatening to publish stolen data if demands were not met. This is an attacker-side claim and has not been confirmed as a ransomware incident in Devereux’s official notice, which describes only unauthorized access and file copying. A data breach class action lawsuit, Williams v. The Devereux Foundation, was filed on January 23rd, 2026 in the U.S. Eastern District of Pennsylvania, alleging that inadequate data security led to a breach exposing sensitive medical records, Social Security numbers, and personal health information—though these are plaintiff allegations in the complaint, not facts confirmed by Devereux’s official notice. Law firms Edelson Lechtzin LLP and Federman & Sherwood have also announced investigations into class action claims related to the breach.
Key Facts at a Glance
- Company or Organization: Devereux Foundation (d/b/a Devereux Advanced Behavioral Health)
- Industry: Behavioral healthcare / Nonprofit
- Location: Villanova, PA, with operations in 13 U.S. states
- Incident type: Unauthorized access and file copying; ransomware involvement claimed by threat actor “The Gentlemen” (unconfirmed by Devereux)
- Date of breach: November 6th, 2025
- Date breach discovered: November 9th, 2025
- Date of consumer notification: July 23rd, 2026
- Litigation status: Williams v. The Devereux Foundation class action filed January 23rd, 2026 in E.D. Pa.; additional investigations announced by Edelson Lechtzin LLP and Federman & Sherwood
- Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-626965); ClaimDepot (https://www.claimdepot.com/data-breach/the-devereux-foundation-2026); DeXpose (https://www.dexpose.io/the-gentlemen-target-devereux-advanced-behavioral-health-in-ransomware-attack/); Law.com Radar (https://www.law.com/radar/card/pm-62718054-williams-v-the-devereux-foundation/)
What Should You Do?
If you received a notice from Devereux Foundation, enroll in the complimentary Experian credit monitoring as soon as possible using the instructions provided in your notice. You should also consider placing a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—to help prevent new accounts from being opened in your name. Review your account statements carefully for any unfamiliar charges or activity, and obtain your free credit reports at AnnualCreditReport.com to check for errors or signs of fraud. If you believe your information is being misused, visit IdentityTheft.gov for step-by-step guidance. Because the breach reportedly may have involved clinical and health-related information, you should also review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.