American Addiction Centers (AAC), disclosed another data breach, this time involving a third-party vendor and the company’s <a href="https://bitcomme.com/salesforce-stock-advances-on-strong-cloud-demand-and-profit-growth/” title=”Salesforce stock advances on strong cloud demand and profit growth”>Salesforce environment. The center had previously disclosed a 2024 data breach that affected 410,000 people.
On May 12, 2026, an unauthorized third party acquired certain information from American Addiction Centers’ Salesforce instance, according to the company’s notification to consumers.
AAC did not immediately detect the unauthorized access. It was not until June 5, 2026, nearly a month after the breach took place, that the company noticed suspicious activity in its Salesforce environment. AAC put its incident response protocols into action, took steps to contain the activity and launched an investigation into the scope of the incident.
The exposed data included both personally identifiable information and health-related details including names, contact information, Social Security numbers and brief descriptions of health conditions.
According to the company’s notice, this information was not pulled from its electronic health records application. It was limited to what individuals had shared during their initial outreach to AAC, such as when first contacting the company to ask about treatment options.
The breach was reported to the California Attorney General on Aug. 7, 2026 and the company has been notifying affected individuals by mail.
American Addiction Centers’ response
The company said it does not currently have evidence that the exposed information has been or will be misused. However, out of an abundance of caution, AAC is providing affected individuals with a complimentary membership to Privacy Solutions ID, an identity protection service offered through Epiq.
The Privacy Solutions ID service includes several layers of protection. These include but are not limited to one-bureau credit monitoring with alerts for key changes such as credit inquiries, new accounts and public records.
Affected individuals can enroll in the service online at Privacy Solutions ID using the unique activation code included in their notification letter. Enrollment must be completed by the deadline specified in each person’s letter.
AAC has also set up a dedicated call center for questions about the breach. Affected individuals can call 1-888-650-3763, available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time.
Those who need help with the Privacy Solutions ID enrollment process can contact Epiq directly at 866-675-2006, available Monday through Friday from 9 a.m. to 5:30 p.m. Eastern Time.
