LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › American Addiction Centers Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

American Addiction Centers Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 7, 2026
American Addiction Centers Data Breach Notice (Washington Attorney General)

Occurred May 12, 2026 · publicly disclosed August 7, 2026. Approximately 1155 people affected.

CRITICAL
Severity
1155
People affected
4
Data types exposed
August 7, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

American Addiction Centers notified the Washington Attorney General of a data breach that occurred on May 12, 2026 and was disclosed on August 7, 2026, exposing the personal information of 1,155 individuals. Anyone who received services from the organization is advised to review the notice and consider protective steps such as monitoring accounts or placing a credit freeze.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1155 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For people who have sought treatment or related services through American Addiction Centers, a formal notice filed with Washington State authorities means personal and medical details may have been exposed in a cyber incident. The filing reports that 1,155 people were affected and that the information involved included names, Social Security numbers, health insurance policy or ID numbers, and medical information. That combination matters because it can support identity theft, insurance fraud, and unwanted contact tied to sensitive health circumstances.

American Addiction Centers notified Washington residents in a filing reported to the Washington State Attorney General on August 07, 2026. The same notice places the incident itself on May 12, 2026. Public detail beyond those points is limited to what the filing states; readers should treat the disclosed data types and the affected count as the confirmed core of the record, not as a full technical postmortem.

What happened

According to the Washington Attorney General filing reported on August 07, 2026, American Addiction Centers experienced a data breach with an incident date of May 12, 2026. The organization notified Washington residents, and the notice lists name, Social Security number, health insurance policy or ID number, and medical information among the information exposed. The filing puts the number of people affected at 1,155.

How the intrusion began, how long unauthorized access lasted, whether systems were encrypted or exfiltrated in bulk, and whether any ransom or extortion demand was involved are not described in the provided facts. No threat group is attributed. The public record available here is a regulatory-style breach notice focused on who was told, when the incident was dated, how many people were counted as affected, and which categories of data were named as exposed.

How a breach like this happens

Incidents that lead to notices naming names, government identifiers, insurance numbers, and medical information often follow familiar patterns in healthcare and behavioral-health environments, even when a specific method is not disclosed for a given case. Attackers commonly obtain an initial foothold through phishing that captures employee credentials, through stolen or reused passwords on remote access portals, or through unpatched software on internet-facing systems. Once inside, they may move laterally to file shares, electronic health record systems, billing platforms, or backup stores where concentrated patient and insurance data reside.

In many organizations, the same systems that support care coordination also hold identity and payment-related fields. If logging is incomplete or alerts are missed, data can be copied without immediate detection. Sometimes the first clear signal is unusual outbound traffic, a ransom note, or later discovery during an investigation. None of that sequence is confirmed for this incident; it is general background on how breaches of this type typically unfold when detailed forensics are not part of the public notice.

American Addiction Centers and its sector

American Addiction Centers operates in the addiction treatment and behavioral-health sector, where organizations typically manage intake, clinical care, billing, and insurance interactions for people seeking help with substance use and related conditions. Entities in this field routinely hold highly sensitive records: identifying information, clinical notes or diagnoses, treatment history, and insurance identifiers needed to authorize and pay for care.

A breach in this sector is consequential because the data are dual-use. Identity fields can be abused for financial fraud, while medical and treatment-related information can cause privacy harm, stigma, or targeted scams that reference a person’s health situation. Regulatory notice requirements exist in part because residents and patients cannot easily change a Social Security number or unwind the exposure of health details the way they might cancel a single credit card. The Washington filing reflects that disclosure obligation for affected residents in that state; it does not, by itself, describe the full national footprint of the organization’s operations or every system involved.

What was likely exposed

The notice explicitly lists the following as among the information exposed: name, Social Security number, health insurance policy or ID number, and medical information. Those categories come directly from the filing and should be treated as the confirmed named types for this notice.

Exact file names, full record layouts, whether every affected person had every field present, and whether additional unlisted fields were involved are not detailed in the facts provided. Organizations of this kind typically also maintain addresses, dates of birth, contact details, and richer clinical documentation in the ordinary course of care, but those items are not stated as exposed in the given summary. Where the public notice is silent, the precise contents remain unconfirmed beyond the four named categories and the count of 1,155 people affected.

What's at stake

For affected individuals, the practical risks center on identity theft and fraud that misuse a name paired with a Social Security number, and on insurance-related fraud or account takeover attempts that misuse policy or member ID numbers. Medical information exposure can enable highly tailored phishing or social-engineering attempts and can create lasting privacy concerns, especially in the context of addiction treatment, where confidentiality is often central to a person’s willingness to seek care.

For the organization, stakes include regulatory scrutiny, notification and support costs, potential civil claims, and erosion of trust among patients and referral partners. Operational disruption can follow if systems must be taken offline for investigation or remediation, though no operational impact is described in the facts here. The gap between the May 12, 2026 incident date and the August 07, 2026 reporting of the Washington notice also means some people may only learn of the exposure months after the event, which can delay protective steps.

What to do if you're exposed

If you believe you may be among those notified, or if you received a letter referencing this incident, treat the named data types seriously. Place a fraud alert or credit freeze with the major credit bureaus, and monitor credit reports and Explanation of Benefits statements for unfamiliar activity. Be cautious of unsolicited calls or messages that reference treatment, insurance, or “breach assistance,” and verify any offer through official channels you initiate yourself. Consider documenting the notice date and keeping copies of any correspondence.

If your Social Security number was involved, review IRS and Social Security account activity where available and report clear misuse promptly. For medical and insurance identifiers, watch for unexpected bills or coverage changes. As a further check, readers can run a free exposure scan of their email to see whether their information has already surfaced in known breach data sets, then prioritize password changes and multi-factor authentication on important accounts. Public detail on this incident remains limited to the Washington Attorney General filing summary; further official updates from the organization or regulators, if any, should be read against the same standard—only what is stated, not what is assumed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyAmerican Addiction Centers security record
56/100
DoxxScan™ · Elevated doxx risk
D- 44Very poor record

2 reported incidents on record.

See American Addiction Centers’s full breach history →
RelatedMore incidents at American Addiction Centers

More recent breaches

Chelan County, WA Data Breach Notice (Washington Attorney General)August 11, 2026Kovack Financial, LLC Data Breach Notice (Washington Attorney General)August 10, 2026Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)August 7, 2026Aesto, LLC (Grant County Public Hospital District #2) Data Breach Notice (Washington Attorney General)August 4, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the American Addiction Centers Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram