BestCare Treatment Services Reports Data Breach in Oregon
BestCare Treatment Services, Inc. reported a data breach to the Oregon Attorney General's office on September 8, 2026, stemming from an incident on June 15, 2026. This security event exposed sensitive personal and health information, including Full Name, Social Security Number, and Diagnosis and Treatment Information, raising significant risks for affected individuals.
- State
- Oregon
- Breach date
- June 15, 2026
- Reported
- September 8, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
BestCare Treatment Services, Inc., a healthcare provider operating in Oregon, filed a report with state regulators on September 8, 2026, confirming a data security incident that occurred on June 15, 2026. The investigation into this breach is currently described as monitoring.
As a specialized healthcare and behavioral health provider, BestCare handles a significant volume of sensitive patient data. Their operations involve managing complete electronic health records and clinical notes, making them a target for malicious actors seeking high-value personal and medical information.
The reported exposure from this incident includes several categories of protected data. Individuals may have had their Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates compromised. The unauthorized access to these data types can lead to severe consequences, including identity theft, medical fraud, and privacy violations.
Security incidents within the healthcare sector often involve unauthorized intrusions into clinical database networks or compromises affecting third-party vendors. Such events can grant malicious actors access to internal administrative systems and patient management portals. The ongoing investigation will aim to clarify the specific mechanisms of this particular incident, with details drawn from public filings with regulators.
Individuals who receive notification about this breach should consider taking steps to protect their information. It is advisable to review account statements for any suspicious activity and monitor credit reports for unauthorized accounts or inquiries. Placing a fraud alert or security freeze on credit files with major credit bureaus can also help prevent unauthorized use of personal identifiers. Regularly changing passwords for online accounts and being vigilant against phishing attempts are also recommended general precautions.
Source: Oregon Attorney General filing