Healthcare provider · Addiction treatment and rehabilitation · Behavioral health network · USA
Addiction treatment provider operating rehab and recovery programs.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In September 2024, American Addiction Centers suffered a ransomware attack attributed to the Rhysida group, detected around September 26, 2024. Rhysida claimed to have exfiltrated approximately 2.8 terabytes of data and published it online after the incident. AAC notified 422,424 individuals on December 23, 2024. Exposed data included names, Social Security numbers, dates of birth, addresses, phone numbers, medical record numbers, treatment/medical information, and health insurance information. The breach is catalogued by DataBreach.com (whose parse cited 528,343 records) and reported to state regulators; AAC offered credit monitoring and later reached a class-action settlement.
American Addiction Centers (AAC) is a Tennessee-based national provider of substance-use and behavioral-health treatment, operating a network of inpatient and outpatient rehabilitation facilities across the United States. It delivers detox, residential, and outpatient addiction treatment along with mental-health services, maintaining detailed clinical, insurance, and billing records for patients in recovery.
Addiction treatment networks collect highly sensitive patient data, including identity records, SSNs, home addresses, insurance information, medical record details, and treatment-related health data.
AAC continues to operate its national treatment network. After the September 2024 ransomware attack it notified 422,424 individuals, offered credit monitoring, and faced multiple class-action lawsuits, which it resolved through a reported $2.75 million settlement. The incident drew particular scrutiny because substance-use treatment records carry heightened federal protection under 42 CFR Part 2.
The breach exposed identity, contact, and clinical data, including Social Security numbers and addiction-treatment information, for more than 422,000 patients, a population for whom disclosure of treatment status carries severe stigma. Beyond identity-theft and medical-fraud risk, the exposure created acute potential for extortion and discrimination, eroded patient trust in a highly sensitive care setting, and generated significant legal and regulatory consequences.
• Extortion and stigma-based targeting exploiting addiction-treatment status | • Medical identity fraud and insurance abuse using health and insurance data | • Identity theft and synthetic identity construction using SSN and DOB | • Targeted phishing and vishing using name, email, and phone | • Doxxing and physical targeting from exposed home addresses | • Discrimination risk from disclosure of substance-use treatment
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware-as-a-service group using double extortion. CISA reporting notes targeting across education, manufacturing, IT, government, and healthcare.
Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.
We will only reveal whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation