Skip to content
Back to Blog
low severity January 28, 2026 · 4 min read

BestCare Treatment Services, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from BestCare Treatment Services, Inc., here’s what the filing says was exposed, and what to do about it.

BestCare Treatment Services, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on January 28, 2026. The filing puts the incident itself on November 01, 2024.

BestCare Treatment Services, Inc. Data Breach Notice (Oregon Attorney General)

The data breach at BestCare Treatment Services, Inc. means that personal information belonging to 1,668 people is now outside the organisation’s control. The filing lists personal information as exposed in the incident that occurred on November 01, 2024. The organisation submitted its notification to the Oregon Department of Justice on January 28, 2026 — an interval of 453 days, or roughly 14.9 months.

What the 453-Day Gap Changes for You

That length of time between the incident and the filing is the single most noticeable fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the gap is long enough that anyone who interacted with BestCare Treatment Services around or before November 2024 should treat the exposure as something that has had more than a year to circulate. The record does not disclose when the organisation discovered the incident, so the only reliable way to know whether your information was included remains the notification letter itself.

The Information That Was Exposed

The filing names personal information as the category involved. No passwords, no financial account numbers, no Social Security numbers, and no government-issued identifiers such as driver’s license or passport numbers appear in the disclosed categories. This is genuinely good news: the absence of these high-value identifiers removes several of the most common pathways used in large-scale identity theft.

Because the exposed category is described only as “personal information,” the exact fields are not detailed beyond that. In the context of a treatment services provider, this most likely includes basic contact details and elements of your treatment or billing records. Health-related data carries lifelong sensitivity. Even without a Social Security number attached, medical information can be used in fraud schemes, insurance abuse, or targeted phishing that references your history with the provider.

Why This Exposure Remains Valuable to Criminals

Personal information tied to a healthcare provider does not lose its usefulness over time the way a credit card number does. Criminals combine it with data obtained elsewhere to build convincing profiles. A name paired with treatment details can support fraudulent insurance claims, prescription fraud, or impersonation when dealing with other medical offices or government agencies. The 453-day window increases the chance that this information has already been packaged and shared on underground markets.

The record establishes that 1,668 Oregon residents were affected. It does not state that every person had the same fields exposed. Your own notification letter is the only document that can confirm exactly which pieces of your information were included.

How to Determine Whether You Were Affected

BestCare Treatment Services is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely that your records were not part of the 1,668 affected. However, if you have moved since November 01, 2024, the letter may have gone to an old address. In that case, contact the organisation directly to confirm whether you were included in the incident.

What You Can Still Control

Although some of the exposed information cannot be changed, your response still matters. Because no credentials were exposed, you do not need to change any password associated with BestCare Treatment Services. That risk does not exist here.

The exposure does mean you should watch for misuse of your medical or personal details. Fraudsters may attempt to file claims in your name or use your history to sound credible when contacting you or your insurers. Early detection is the most effective protection.

Practical Steps Specific to This Incident

  • Review your Explanation of Benefits statements from every insurer you have used since late 2024. Look for claims you did not file or treatment you did not receive. Medical fraud often appears here first.
  • Contact BestCare Treatment Services and ask for a copy of the exact record that was exposed. Knowing the precise fields lets you monitor the right accounts and respond more effectively if fraud appears.
  • Place a fraud alert with the three major credit bureaus. Even without a Social Security number listed in the filing, the combination of personal and health details can support identity theft attempts that eventually reach credit files.
  • Monitor medical bills and insurance correspondence for at least the next 24 months. Healthcare-related fraud can surface long after the initial breach.
  • Be wary of unsolicited contact that references your treatment history at BestCare. Use this as a verification signal: legitimate organisations will not cold-call or email you with specific details of your care without first confirming your identity through established channels.

The core reality is straightforward. Your personal information left BestCare Treatment Services’ systems on or around November 01, 2024. The organisation took more than 14 months to notify the state. No passwords or high-value identifiers were listed as exposed, which significantly limits the immediate danger, but the health-related personal information that was exposed will remain sensitive for the rest of your life. The letter you did or did not receive is still the clearest indicator of whether this specific incident concerns you. Where uncertainty remains, direct confirmation with the provider is the only step that closes the loop.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed January 28, 2026
Last reviewed July 22, 2026
Affected 1668
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email