What Happened in the American Addiction Centers Data Breach?
American Addiction Centers, a treatment provider that helps people struggling with substance abuse, has confirmed a data security incident tied to a third-party vendor. The company discovered suspicious activity inside its Salesforce environment on June 5, 2026. As a result, its team quickly activated incident response protocols to contain the threat.
Just three days later, on June 8, 2026, investigators determined that an unauthorized third party had actually pulled information out of the Salesforce system. That intrusion itself is believed to have occurred on May 12, 2026. Importantly, the company has stated that this incident did not touch its core network, broader systems, or its electronic health records application.
Instead, the exposed data came from a more limited source: information collected during initial outreach conversations with the organization. Because Salesforce is often used to manage early customer or patient inquiries, this distinction matters. However, it does not change the fact that sensitive personal details were taken.
Following discovery, American Addiction Centers launched a forensic investigation to understand the scope of the intrusion. The company also began working to identify every individual whose data may have been involved. This process ultimately led to formal notification letters being sent to affected individuals in August 2026.
Who was affected?
The individuals affected by this breach appear to be people who reached out to American Addiction Centers, likely seeking help or information about treatment programs. Because the compromised data came from an early outreach system rather than a full patient record system, those affected may include prospective patients as well as existing ones.
American Addiction Centers has not publicly disclosed the total number of individuals affected by this incident. Given the sensitive nature of addiction treatment inquiries, this breach could carry an especially high personal impact for those involved, since many people take great care to keep such information private.
What Information Was Potentially Exposed?
According to the notification letter, the breach involved a specific and sensitive combination of personal details. This information was accessed directly from the compromised Salesforce instance rather than from the company’s health records systems.
- Full name
- Contact information
- Social Security number
- A brief description of the individual’s health, as provided during outreach
This combination of data creates real risk for identity theft. A Social Security number paired with a name and contact details gives criminals nearly everything needed to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Because this type of fraud can take months to detect, affected individuals should stay alert for a long time after this notice.
In addition, the exposure of health-related descriptions raises a separate and deeply personal concern. Even a brief mention of a health condition, especially one tied to addiction treatment, could be misused for targeted scams or embarrassment if it falls into the wrong hands. As a result, affected individuals should treat both the financial and personal privacy risks from this breach seriously.
What is the company doing?
American Addiction Centers has stated that it takes the security of personal information seriously. In direct response to this incident, the company implemented immediate containment measures once it detected suspicious activity in its Salesforce environment.
Beyond the initial response, the company says it has added extra safeguards to better protect and monitor its Salesforce environment going forward. This is meant to reduce the chance of a similar incident happening again. In addition, American Addiction Centers is offering affected individuals a complimentary membership to Privacy Solutions ID, a credit monitoring and identity protection service provided through Epiq.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Because Social Security numbers were exposed, affected individuals should watch their credit reports closely in the months ahead. Unexpected accounts, unfamiliar inquiries, or sudden changes in your credit score can all be early warning signs of fraud.
You can request a free credit report from each of the three major credit bureaus once every 12 months through annualcreditreport.com. For example, checking one bureau every four months lets you monitor your credit throughout the year at no cost.
Consider a Credit Freeze or Fraud Alert
Given that Social Security numbers were involved, placing a credit freeze is one of the strongest steps you can take. A freeze blocks lenders from accessing your credit file, which makes it much harder for identity thieves to open new accounts in your name.
Alternatively, a fraud alert requires businesses to verify your identity before extending credit. This option is less restrictive than a freeze but still adds an important layer of protection. You can request either option directly through Equifax, Experian, or TransUnion.
Enroll in the Offered Identity Protection Service
Since American Addiction Centers is offering a complimentary membership to Privacy Solutions ID through Epiq, affected individuals should strongly consider enrolling before the deadline stated in their letter. This service includes credit monitoring, dark web monitoring, and identity restoration assistance.
To enroll, visit the activation website listed in your notification letter and follow the enrollment steps provided. Because these memberships often have a limited enrollment window, acting quickly helps ensure you don’t miss out on this protection.
Watch for Phishing Attempts
After a breach like this, scammers often try to exploit fear by sending fake emails or texts pretending to be from the affected company. These messages may ask you to click suspicious links or provide additional personal information.
Therefore, always verify communications independently by contacting the company through a known, official phone number. Never provide sensitive details like your Social Security number or login credentials in response to an unsolicited message.
Review Health Insurance and Provider Statements
Because a brief description of health information was also exposed, it’s wise to review statements from your health insurer or healthcare providers. Look closely for any charges or services listed that you don’t recognize.
If you spot anything unusual, contact your insurer or provider right away to dispute it. Catching medical identity fraud early can prevent larger complications with your medical records and insurance coverage down the road.
More Information
Official data breach notification from California Attorney General
Official data breach notification from Oregon Department of Justice
