American Addiction Centers Reports Oregon Patient Data Breach
American Addiction Centers reported a data breach in Oregon on September 3, 2026, involving patient information exposed since June 5, 2026. The exposed data includes highly sensitive personal and health details, potentially impacting individuals who received care.
- State
- Oregon
- Breach date
- June 5, 2026
- Reported
- September 3, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
- Billing and Financial Information
American Addiction Centers, a national provider of substance use disorder treatment, reported a data security incident to Oregon regulators on September 3, 2026. The company indicated that private information was exposed starting June 5, 2026. The nature of the breach was unspecified in the public filing, and an investigation is currently monitoring the situation.
The exposed categories of personal information include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, Provider and Treatment Dates, and Billing and Financial Information. This comprehensive set of data contains highly sensitive details related to an individual's treatment and personal identity.
The compromise of such detailed health and personal records carries significant risks for affected individuals. Exposed information like Social Security Number and Billing and Financial Information can be used for identity theft and various forms of fraud. The release of sensitive medical details, including Diagnosis and Treatment Information and Prescription Information, also poses a risk of medical identity theft, where unauthorized parties could seek medical services or prescription drugs under another's name, potentially corrupting medical histories.
Individuals who receive a notification letter from American Addiction Centers regarding this incident should take steps to protect their information. It is recommended to carefully review any explanation of benefits statements from health insurers for unauthorized services. Monitoring credit reports for suspicious activity and placing a fraud alert or security freeze on credit files can help prevent financial fraud. Additionally, remaining vigilant against unsolicited communications requesting personal details is advisable, as these could be phishing attempts.
Source: Oregon Attorney General filing