American Association of Critical-Care Nurses Data Breach Notice (Oregon Attorney General)
If you received a notice from American Association of Critical-Care Nurses, here’s what the filing says was exposed, and what to do about it.
American Association of Critical-Care Nurses notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 29, 2025.
The American Association of Critical-Care Nurses has notified 57,526 people that their personal information was exposed in a data breach. If you received a letter from the organisation, your records were part of this incident.
Personal information cannot be replaced
The filing lists personal information as the category exposed. That typically includes name, address, date of birth, and in many cases Social Security number. These details do not expire. Once they leave an organisation’s control they remain useful for identity theft, tax fraud, loan applications in your name, and medical identity misuse for years.
No passwords were exposed. The record contains no credential data, so there is no need to change any AACN account password because of this incident. That is one fewer immediate task, but it does not reduce the long-term risk carried by the personal information itself.
What this exposure enables
With a name paired with a Social Security number and date of birth, someone can open credit accounts, file fraudulent tax returns, or impersonate you in healthcare settings. Medical identity theft can lead to incorrect information placed in your health record, which is difficult to correct and can affect future treatment or insurance claims.
The scale — 57,526 individuals — makes this one of the larger notifications filed with Oregon this year. The volume alone increases the chance that the data will circulate among fraud networks that specialise in combining stolen records from multiple sources.
The letter is the only reliable way to know
The Oregon filing does not state when the incident occurred, only that the organisation submitted the notice on August 29, 2025. Because the record gives no incident date, you cannot use time passed since a particular month as a test. The organisation is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, anyone who has moved in recent years should contact the American Association of Critical-Care Nurses directly to confirm whether their records were affected.
Why the risk lasts longer than most people expect
Unlike a credit card number that can be cancelled, a Social Security number cannot be reissued on request. A date of birth never changes. These pieces of information keep their value even after several years on the dark web. Criminals often wait for the initial publicity to fade before using the data in more sophisticated fraud schemes that combine records from different breaches.
The notification itself does not reveal how the breach happened, whether the data was copied or simply viewed, or how long it may have been accessible. Those details remain unknown to the public. What matters for you is what was confirmed to be exposed: personal information belonging to 57,526 people.
Practical steps that address this specific exposure
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion immediately. This is the single most effective way to stop new accounts from being opened in your name using the exposed data.
- Review your Explanation of Benefits statements from every health insurer you use. Look for claims you do not recognise that could indicate medical identity theft.
- File your taxes early each year and monitor for IRS rejection letters. Fraudulent returns filed with your Social Security number are a common consequence of this type of breach.
- Request your free annual credit reports and check them for accounts you did not open. Continue monitoring even after the initial alert period ends.
- Contact the American Association of Critical-Care Nurses directly if you have changed addresses since their last communication with you. Confirm whether your records were in the affected group.
The exposure of personal information at this scale means the prudent assumption is that the data will be used. Early protective steps reduce the chance that it will succeed. The filing establishes that 57,526 individuals were notified; whether you are one of them is answered by the letter you did or did not receive.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…