
Acadia Healthcare Company Inc., one of the largest behavioral healthcare providers in the United States, disclosed a data breach that occurred in March 2026 involving unauthorized access to patient information.
An unauthorized party used social engineering to gain access to one employee email account and an associated SharePoint account at Acadia Healthcare. SharePoint is a Microsoft platform that organizations use to store and share documents and files.
Between March 21 and March 25, 2026, the unauthorized party accessed and obtained certain emails and SharePoint files from these accounts. Upon learning of the incident, the company secured the compromised accounts and launched an investigation with the assistance of a third-party forensic investigation firm.
The investigation confirmed that the breach was limited to the one email account and the associated SharePoint account.
The company then initiated a review to determine the contents of the emails and files that were involved in the incident.
On May 15, 2026, as part of that ongoing review, the company determined that the compromised files contained patient information. The types of information exposed included names, addresses, dates of birth, treatment information, dates of treatment, type of treatment, health insurance information, Medicare Health Insurance Claim Number (HICN) and Social Security number.
Acadia Healthcare began notifying affected individuals on May 22, 2026. The company has posted a notice about the incident on its website. 1,807 total individuals were impacted as a result of the breach, including 405 Massachusetts residents
Acadia Healthcare has set up a dedicated, toll-free incident response line for individuals who have questions about the breach. Affected individuals can call 888-500-5708, Monday through Friday from 8 a.m. to 8 p.m. Central Time, excluding major U.S. holidays.
The notification letter mailed to affected individuals included general information about placing fraud alerts and credit freezes with the three major credit bureaus, as well as guidance on reporting potential identity theft to the Federal Trade Commission and state attorneys general offices.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)