American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
American Addiction Centers, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on December 23, 2024. The filing puts the incident itself on September 23, 2024.
The personal information of 422,424 people was exposed in a breach at American Addiction Centers, Inc. on September 23, 2024. The organisation filed its notification with the Oregon Department of Justice exactly 91 days later, on December 23, 2024.
That three-month gap between the incident and the filing is the most striking detail in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval is long enough to matter to anyone whose records were included.
What the Filing Actually Lists
The record names only one category of exposed data: personal information. No passwords, no financial account numbers, no Social Security numbers, and no medical treatment history appear in the disclosed categories. This is genuinely good news. The absence of those higher-risk identifiers limits what attackers can do with any data that may have been taken.
Because the filing lists only this single broad category, the precise details that reached any one individual will be spelled out in the letter sent directly by American Addiction Centers. The organisation is required to notify affected people by mail using their last known address.
How to Know If You Were Affected
If you have not received a letter from American Addiction Centers, your information was most likely not part of this incident. Letters can be delayed or misdelivered, however. Anyone who has moved since September 23, 2024 should contact the organisation directly to confirm whether their records were involved.
What Permanent Risk Remains
With only generic personal information listed, the exposure does not create the permanent, non-reversible risks that come with Social Security numbers or detailed medical records. Identity thieves cannot open accounts or file fraudulent tax returns with the data described in this filing. The information cannot be “reset” like a credit card, but it also cannot anchor long-term fraud the way a government identifier can.
The real remaining concern is targeted spam, phishing attempts, or impersonation calls that reference your connection to American Addiction Centers. Attackers sometimes use even limited personal details to make fraudulent outreach appear legitimate.
The Value of the Three-Month Delay
A 91-day interval between the September 23 incident and the December 23 filing leaves open questions the record does not answer. The filing is silent on when the breach was discovered, whether data was copied or simply viewed, and what security measures were in place. Those details remain unknown to the public.
What matters most to you is that the exposed category is narrow. The letter you may receive will tell you exactly which pieces of personal information were involved in your case. Until that letter arrives, the safest assumption is that basic contact and identification details are the extent of the exposure.
Practical Steps That Address This Specific Exposure
- Watch for the letter. It remains the only reliable way to know whether you are one of the 422,424 people included. Save any correspondence from American Addiction Centers unopened until you can review it carefully.
- Monitor your mail and email for follow-up contact. Be wary of unsolicited calls or messages claiming to be from the organisation or a partner. Verify any request for information by calling a number listed on their official website rather than one provided in the message.
- Review your credit reports once this year at AnnualCreditReport.com. Even without financial data exposed here, a single breach can be part of a larger pattern. One free report from each of the three bureaus is available weekly.
- Place a fraud alert if you notice any unusual activity. A 90-day fraud alert is quick to file with one credit bureau and automatically notifies the others. It forces creditors to verify your identity before opening new accounts.
- Keep records of any communication you receive. If identity theft does occur later, documentation that your data was exposed in this incident can help resolve disputes with banks or credit agencies.
The record is limited by design. It tells us who filed, when the incident occurred, how many Oregon residents were affected, and which single category of information was involved. Nothing more. The letter you may receive fills in the personal specifics. Until then, the narrow scope of the disclosed data means this breach carries lower long-term risk than many others that expose government identifiers or clinical histories.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Castle Management, LLC Data Breach Notice (Vermont Attorney General)
Castle Management, LLC notified Vermont residents of a data breach in a filing reported to the Vermo…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…