LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·December 23, 2024
American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)

Occurred September 23, 2024 · publicly disclosed December 23, 2024. Approximately 422424 people affected.

MEDIUM
Severity
422424
People affected
1
Data types exposed
December 23, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

American Addiction Centers, Inc. disclosed a data breach on December 23, 2024, affecting 422,424 individuals after an incident that occurred on September 23, 2024. Anyone who received services from the company should review the notice and consider placing fraud alerts or credit freezes if their personal information was exposed.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
422424 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Healthcare and behavioral-health organizations remain frequent targets in today’s threat landscape because the records they hold combine identity details with sensitive personal context. Against that backdrop, American Addiction Centers, Inc. reported a data incident that reached state authorities in late 2024, bringing a large number of individuals into the scope of official notice.

According to a filing with the Oregon Department of Justice, the company notified Oregon residents of a data breach. The notice was reported on December 23, 2024, and places the incident itself on September 23, 2024. Public material identifies roughly 422,424 people as affected and describes the exposed material as personal information. Exact technical method and full contents beyond that label are not laid out in the disclosure summary available here.

What happened

American Addiction Centers, Inc. submitted a data-breach notice that was reported to the Oregon Attorney General’s office / Oregon Department of Justice on December 23, 2024. The filing states that the underlying incident occurred on September 23, 2024. The organization identified 422,424 individuals as affected. The notification characterizes the exposed data as personal information. Public detail in the provided record does not describe how systems were accessed, whether ransomware or another technique was involved, how long unauthorized access lasted, or which specific systems or files were touched. No threat actor is named in the facts.

How a breach like this happens

Incidents that lead to notices of this kind commonly begin with one of several well-known paths. Stolen or guessed credentials can give an outsider a foothold in email, remote-access, or cloud portals. Phishing messages may trick staff into revealing passwords or approving fraudulent multi-factor prompts. Unpatched internet-facing software, misconfigured storage, or compromised vendor connections can also open a route in. Once inside, attackers often move laterally, locate databases or document repositories, and copy data for later use or extortion. In other cases, a ransomware deployment encrypts systems and a data-theft claim is made alongside the disruption. None of these patterns is confirmed for this specific event; they are the general background against which organizations in regulated sectors prepare and respond. Detection may come from security tooling, unusual outbound traffic, a vendor alert, or a third-party notification. Containment typically involves isolating affected systems, resetting credentials, engaging forensic help, and determining what was accessed so that required notices can be issued.

American Addiction Centers, Inc. and its sector

American Addiction Centers, Inc. operates in the addiction-treatment and behavioral-health field. Organizations of this type provide residential and outpatient care, counseling, and related support services. In the ordinary course of business they collect and retain information needed for intake, clinical care, billing, insurance, and ongoing contact with patients and families. That routinely includes names, addresses, dates of birth, contact details, government identifiers, insurance data, and health-related information protected under federal and state privacy rules. Because the sector handles both identity data and sensitive health context, a confirmed or suspected unauthorized access event carries heightened consequences for the people whose records are involved and for the provider’s regulatory and operational obligations. A breach notice from such an organization is therefore consequential even when technical specifics remain limited in public filings.

The information in question

The breach notification, as reflected in the Oregon filing summary, names the exposed material as personal information. It does not itemize further categories in the facts provided here. Organizations in addiction treatment and related healthcare typically hold demographic and contact data, Social Security numbers or other government IDs, insurance and payment details, and clinical or treatment-related records. Whether any or all of those elements were involved in this incident is unconfirmed beyond the general “personal information” label used in the notice. Readers should treat the exact contents as limited in public detail rather than assume a full inventory.

What's at stake

For affected individuals, personal information in the wrong hands can support identity theft, account takeover attempts, targeted phishing that references real personal details, or fraud involving insurance or benefits. When health- or treatment-related context is also present—even if not explicitly confirmed here—the risk of embarrassment, discrimination, or more tailored social-engineering increases. For the organization, consequences can include regulatory scrutiny, notification and credit-monitoring costs, potential civil claims, operational disruption during investigation and remediation, and lasting effects on patient trust. The scale reported—hundreds of thousands of people—means the practical burden of monitoring and response is substantial for both the company and those notified. None of this establishes negligence as fact; it describes the ordinary stakes when personal data held by a behavioral-health provider is implicated in a reported incident.

If your data was in this breach

If you received a notice from American Addiction Centers, Inc., or if you believe you may be among the individuals counted in the Oregon filing, practical first steps are straightforward and do not require technical expertise.

Public detail on method and full data inventory remains limited to what the December 23, 2024 Oregon filing and related notice describe. Further clarity, if any, would come from the organization or subsequent regulatory updates rather than from speculation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyAmerican Addiction Centers, Inc. security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See American Addiction Centers, Inc.’s full breach history →

More recent breaches

Stiiizy Inc. Data Breach Notice (Oregon Attorney General)December 31, 2024Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)December 23, 2024Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)December 20, 2024International Coffee & Tea, LLC Data Breach Notice (Oregon Attorney General)December 19, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram