American Addiction Centers Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
American Addiction Centers notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on August 07, 2026, and the notice lists name, social security number, health insurance policy or id number and medical information among the information exposed. The filing puts the incident itself on May 12, 2026.
The filing from American Addiction Centers confirms that the personal information of 1,155 people was exposed in an incident that occurred on May 12, 2026. The organization notified Washington authorities on August 07, 2026 — an interval of 87 days.
If you received a letter from American Addiction Centers, your name, Social Security number, health insurance policy or ID number, and medical information were among the categories listed in this filing. These details retain their value for identity theft, insurance fraud, and potential blackmail long after the incident. The absence of any password or login credential in the exposed data is genuine good news: no one can use this breach to attempt direct account takeover.
What a Social Security Number and Health Insurance ID Enable
A Social Security number cannot be reissued on request the way a credit card or password can. Combined with your name and medical information, it gives a fraudster the ability to open accounts, file false tax returns, or apply for government benefits in your name. The health insurance ID adds another permanent vector: criminals can submit fake claims, exhaust your benefits, or create medical identity theft that follows you for years through incorrect records in insurance databases.
Medical information itself carries lifelong risk. Details about addiction treatment are especially sensitive. In the wrong hands they can be used for blackmail, employment discrimination, or to build a more convincing synthetic identity when paired with your SSN. Unlike a credit card number, none of these pieces expire or can be simply replaced.
The 87-Day Gap Between Incident and Notification
The breach happened on May 12, 2026. The filing reached the Washington Attorney General on August 07, 2026. That nearly three-month period is the most concrete fact this record provides. Notification timelines vary by state law and by when an internal investigation concludes, so the exact reasons for the interval are not stated. What matters is that the information was outside the organization’s direct control for that length of time before formal notice was filed.
How to Determine Whether You Are Affected
American Addiction Centers is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included in this incident. However, if you have moved since May 12, 2026, or changed addresses at any point after the incident date, contact the organization directly to confirm your status. The letter remains the clearest indicator available.
Why Medical Information Lasts Longer Than Most People Expect
Once medical history tied to your identity leaves controlled systems, it cannot be taken back. Insurance companies, future providers, and employers may encounter altered records created by fraudsters. A false claim filed against your policy can lead to denied coverage or surprise bills years later. The combination of SSN, insurance ID, and treatment details creates a profile valuable enough for long-term exploitation rather than quick resale on dark web markets.
No passwords were exposed. This means the immediate risk is not to any online account you hold with American Addiction Centers. The danger lies entirely in the biographic and medical identifiers that cannot be rotated or retired.
The Scale and What It Does Not Tell Us
Exactly 1,155 individuals are named in this Washington filing. The record does not disclose whether the data was copied and exfiltrated or only viewed. It also does not state the root cause. What it does state clearly is which categories were involved and how many Washington residents were affected.
Concrete Steps That Address This Specific Exposure
- Place a fraud alert or credit freeze with the three major credit bureaus immediately. Your SSN is now in unknown hands; a freeze prevents new accounts from being opened without your explicit permission.
- Review every Explanation of Benefits statement from your health insurer. Look for claims you did not file or services you did not receive. Medical identity theft is often discovered only through these documents.
- Request your free annual credit reports and check for unfamiliar accounts or inquiries. Do this every four months rotating across Equifax, Experian, and TransUnion.
- Contact American Addiction Centers directly if you have changed addresses since May 2026. Confirm whether a notification letter was sent to your previous address.
- Consider identity theft protection services that include medical fraud monitoring. Standard credit monitoring will not catch fraudulent insurance claims or altered medical records.
The exposure of your Social Security number and medical treatment history cannot be undone. What you still control is how quickly and thoroughly you monitor the downstream consequences. Starting with a credit freeze and systematic review of insurance statements gives you the strongest practical defense against the risks created by this incident.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on American Addiction Centers.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…