American Addiction Centers Discloses Another Data Breach

Published
August 9, 2026
Updated
August 9, 2026
American Addiction Centers Discloses Another Data Breach
American Addiction Centers
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

American Addiction Centers (AAC), disclosed another data breach, this time involving a third-party vendor and the company's Salesforce environment. The center had previously disclosed a 2024 data breach that affected 410,000 people.

On May 12, 2026, an unauthorized third party acquired certain information from American Addiction Centers' Salesforce instance, according to the company's notification to consumers.

AAC did not immediately detect the unauthorized access. It was not until June 5, 2026, nearly a month after the breach took place, that the company noticed suspicious activity in its Salesforce environment. AAC put its incident response protocols into action, took steps to contain the activity and launched an investigation into the scope of the incident.

By June 8, 2026, the investigation confirmed that the unauthorized access had occurred.

The exposed data included both personally identifiable information and health-related details including names, contact information, Social Security numbers and brief descriptions of health conditions.

According to the company's notice, this information was not pulled from its electronic health records application. It was limited to what individuals had shared during their initial outreach to AAC, such as when first contacting the company to ask about treatment options.

The breach was reported to the California Attorney General on Aug. 7, 2026 and the company has been notifying affected individuals by mail.

American Addiction Centers' response

The company said it does not currently have evidence that the exposed information has been or will be misused. However, out of an abundance of caution, AAC is providing affected individuals with a complimentary membership to Privacy Solutions ID, an identity protection service offered through Epiq.

The Privacy Solutions ID service includes several layers of protection. These include but are not limited to one-bureau credit monitoring with alerts for key changes such as credit inquiries, new accounts and public records.

Affected individuals can enroll in the service online at Privacy Solutions ID using the unique activation code included in their notification letter. Enrollment must be completed by the deadline specified in each person's letter.

AAC has also set up a dedicated call center for questions about the breach. Affected individuals can call 1-888-650-3763, available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time.

Those who need help with the Privacy Solutions ID enrollment process can contact Epiq directly at 866-675-2006, available Monday through Friday from 9 a.m. to 5:30 p.m. Eastern Time.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image