If you received a notification from American Addiction Centers, your personal information was included in a data incident the organization reported to California regulators. The filing lists personal information per the breach notification but contains no passwords, no permanent government identifiers such as Social Security numbers, and no financial account details. No passwords were exposed.
That single fact removes the most immediate account takeover risk many people fear after a breach. You do not need to change any password for American Addiction Centers because none was taken. What remains exposed, however, cannot be undone. Medical and addiction treatment history are among the categories listed. Once that information leaves an organization it stays permanently sensitive. It can be used for identity fraud, insurance fraud, employment discrimination, or targeted harassment based on stigma.
The Categories Listed in the Filing
The record names personal information as defined under California breach notification law. It does not disclose the exact fields accessed for every individual, nor does it state how many people were affected. The filing simply confirms that personal information was involved. Anyone who received a letter from the organization is the only person who can know precisely which details applied to them. If you have not received such a letter, the organization was not required to notify you.
What Medical and Treatment History Exposure Actually Means
Addiction treatment records carry unique weight. They can reveal diagnoses, medications, therapy notes, admission dates, and discharge summaries. Insurers, employers, landlords, or even family members who obtain this data can draw conclusions that affect coverage, hiring, housing, or personal relationships. Unlike a credit card number, these records cannot be reissued. The exposure is permanent.