LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Acadia Healthcare Company, Inc. Data Breach Notice (Massachusetts Attorney General)

CRITICAL severityConfirmedHow we verify

Acadia Healthcare Company, Inc. Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 22, 2026
Acadia Healthcare Company, Inc. Data Breach Notice (Massachusetts Attorney General)

Reported May 22, 2026. Approximately 405 people affected.

CRITICAL
Severity
405
People affected
1
Data types exposed
May 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Acadia Healthcare Company, Inc. has disclosed a data breach affecting 405 individuals, exposing medical records, as noted in a filing with the Massachusetts Attorney General on May 22, 2026. Individuals who received services from Acadia Healthcare should verify whether their information was involved and review any guidance provided by the company or state authorities.

Severity & verification
CRITICAL severityConfirmed
Exposes medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
405 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a healthcare sector already strained by repeated cyber incidents that put clinical and personal information at risk, Acadia Healthcare Company, Inc. has disclosed a data breach affecting a defined group of people. The company notified Massachusetts residents through a filing reported to the Massachusetts Office of Consumer Affairs on May 22, 2026. Public detail is limited, yet the notice lists medical records among the information exposed and states that 405 people were affected.

Even a relatively contained notice matters because medical records are among the most sensitive categories of personal data. They can support identity misuse, insurance fraud, and long-term privacy harm that is difficult to reverse. This article sets out what the disclosure actually says, what remains undisclosed, and what affected individuals can reasonably do next.

Breaking down the breach

According to the breach notice associated with the Massachusetts Attorney General’s reporting channel, Acadia Healthcare Company, Inc. informed Massachusetts residents of a data breach in a filing reported on May 22, 2026. The filing indicates that 405 people were affected. Among the information described as exposed are medical records.

The public record provided here does not describe how the incident began, whether it involved ransomware, phishing, a compromised vendor, misconfigured storage, or another cause. It does not state when unauthorized access first occurred, how long it lasted, or when it was contained. It does not name a threat actor, publish forensic findings, or detail which systems or file repositories were involved. Those elements are undisclosed in the facts available for this account.

What is established is narrower and clearer: a formal notice to Massachusetts authorities and residents, a stated affected count of 405, and medical records listed among the exposed data types. Readers should treat any broader claims circulating outside that notice as unconfirmed unless the company or a regulator later expands the record.

How a breach like this happens

Incidents that lead to notices involving medical records often follow familiar patterns, even when a specific case does not publish its root cause. Attackers commonly obtain an initial foothold through stolen or guessed credentials, phishing messages that harvest logins, vulnerable remote-access services, or weaknesses in third-party software used for billing, scheduling, or records management. Once inside, they may move laterally, search for file shares or databases that hold clinical documentation, and copy data for later misuse or extortion.

In other cases, exposure is less about an active intruder and more about access-control failures: a cloud bucket left reachable, an email sent to the wrong recipient, a departed employee’s account left active, or a vendor connection that was broader than necessary. Healthcare environments are especially complex because clinical care, revenue-cycle systems, and patient portals often interconnect, and many organizations rely on outside service providers. That complexity can enlarge the path an attacker or an error can take.

None of these general patterns should be read as a finding about Acadia’s incident. No method is attributed in the disclosure summarized here. The background is offered only so readers understand why medical-record breaches recur across the sector and why organizations issue formal notices when protected health information may have been accessed or acquired without authorization.

Who is Acadia Healthcare Company, Inc.?

Acadia Healthcare Company, Inc. is a large U.S. provider in the behavioral health field, operating facilities and programs that typically include psychiatric care, substance-use treatment, and related clinical services. Organizations of this type routinely create and maintain medical records, treatment histories, insurance and billing details, and identifying information needed to deliver and document care.

A breach at a behavioral health provider is consequential for reasons that go beyond ordinary identity theft. Clinical notes and diagnoses can be highly personal. Unauthorized exposure can affect employment, relationships, insurance interactions, and a person’s sense of safety. Regulators treat health data under heightened expectations precisely because the harm is not only financial. When a company notifies state authorities—as Acadia did in the Massachusetts filing reported on May 22, 2026—it is acknowledging a privacy event with potential real-world effects for the people named in its notice population.

What was likely exposed

The facts name medical records as a data type exposed in this incident. Beyond that label, the public summary does not itemize fields such as diagnoses, medications, lab results, treatment notes, Social Security numbers, addresses, or insurance identifiers. Exact contents of the medical records at issue are therefore unconfirmed in the material provided.

Organizations in Acadia’s sector typically hold charts and related documentation that can include patient identifiers, clinical assessments, progress notes, prescriptions, and billing or insurance data tied to care. It is reasonable for affected people to assume that health-related information was in scope because the notice lists medical records, but it is not accurate to assert any narrower data element as proven fact unless a later official notice does so. The confirmed points remain the affected count of 405, the May 22, 2026 reporting date in Massachusetts, and medical records among the exposed categories.

Why it matters

For individuals, exposure of medical records can enable targeted scams that reference real treatment details, attempts to obtain medical services or prescriptions in someone else’s name, and fraudulent insurance claims. Unlike a payment-card number, clinical history cannot be “reissued.” People may also face lasting anxiety about who has seen sensitive information, especially in behavioral health contexts where stigma remains a practical concern.

For the organization, a notice of this kind brings regulatory attention, notification costs, potential credit-monitoring or support obligations, and reputational pressure from patients, partners, and payers. The relatively modest headcount of 405 does not make the event trivial for those included; it does suggest a bounded population rather than an unbounded mass disclosure, based solely on the figure reported. Still, without public detail on method or dwell time, outside observers cannot independently judge the full operational impact.

Broader trust in digital health systems also erodes when successive notices accumulate. Patients need confidence that the systems holding their care history are monitored and that organizations will communicate clearly when something goes wrong. Clear, limited disclosures—stating what is known and what is not—help more than speculation.

If your data was in this breach

If you received a notice from Acadia Healthcare Company, Inc., or if you are a Massachusetts resident who believes you may be among the 405 people referenced, read the letter carefully and keep it. Follow any instructions the company provides for support or monitoring. Consider placing fraud alerts or credit freezes through the major credit bureaus if identifiers beyond clinical data may also have been involved, and watch insurance explanations of benefits for care you did not receive. Be cautious of unsolicited calls or messages that reference your treatment; verify contacts through official channels rather than numbers supplied in unexpected outreach.

Review your medical-portal accounts for unfamiliar activity, update passwords to unique credentials, and enable multi-factor authentication where available. If you work with a clinician or insurer on corrections to your record, document those requests. Finally, readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data, which can help prioritize further monitoring even when a single notice is limited in detail.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyAcadia Healthcare Company, Inc. security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Acadia Healthcare Company, Inc.’s full breach history →

More recent breaches

Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)August 27, 2026Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026The Health Trust and its subsidiary, FASS Data Breach Notice (Massachusetts Attorney General)August 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Acadia Healthcare Company, Inc. Data Breach Notice (Massachusetts Attorney General) →

Source: Massachusetts Office of Consumer Affairs breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram