American Addiction Centers 2024 Data Breach

American Addiction Centers Behavioral Health Network Breach (2024): 422K Patient Records Including Medical Diagnosis & SSN Exposed via Ransomware

Healthcare provider · Addiction treatment and rehabilitation · Behavioral health network · USA

American Addiction Centers Behavioral Health Network Breach (2024): 422K Patient Records Including Medical Diagnosis & SSN Exposed via Ransomware

Addiction treatment provider operating rehab and recovery programs.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
87/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
422KRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
PHI / MedicalMedical Diagnosis; Medical Record Number
AddressPhysical address
Classification Tags
RhysidaRansomware / ExtortionHealthcareAddictionPatients2024

Breach Summary

In September 2024, American Addiction Centers suffered a ransomware attack attributed to the Rhysida group, detected around September 26, 2024. Rhysida claimed to have exfiltrated approximately 2.8 terabytes of data and published it online after the incident. AAC notified 422,424 individuals on December 23, 2024. Exposed data included names, Social Security numbers, dates of birth, addresses, phone numbers, medical record numbers, treatment/medical information, and health insurance information. The breach is catalogued by DataBreach.com (whose parse cited 528,343 records) and reported to state regulators; AAC offered credit monitoring and later reached a class-action settlement.

About American Addiction Centers

American Addiction Centers (AAC) is a Tennessee-based national provider of substance-use and behavioral-health treatment, operating a network of inpatient and outpatient rehabilitation facilities across the United States. It delivers detox, residential, and outpatient addiction treatment along with mental-health services, maintaining detailed clinical, insurance, and billing records for patients in recovery.

Why They Hold Your Data

Addiction treatment networks collect highly sensitive patient data, including identity records, SSNs, home addresses, insurance information, medical record details, and treatment-related health data.

Recent Developments

AAC continues to operate its national treatment network. After the September 2024 ransomware attack it notified 422,424 individuals, offered credit monitoring, and faced multiple class-action lawsuits, which it resolved through a reported $2.75 million settlement. The incident drew particular scrutiny because substance-use treatment records carry heightened federal protection under 42 CFR Part 2.

Data Points Exposed

9 verified field types
Date of Birth High
Email Address
Full Name
Health Insurance
Medical Diagnosis Critical
Medical Record Number High
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

The breach exposed identity, contact, and clinical data, including Social Security numbers and addiction-treatment information, for more than 422,000 patients, a population for whom disclosure of treatment status carries severe stigma. Beyond identity-theft and medical-fraud risk, the exposure created acute potential for extortion and discrimination, eroded patient trust in a highly sensitive care setting, and generated significant legal and regulatory consequences.

Exploitation & Downstream Threats

• Extortion and stigma-based targeting exploiting addiction-treatment status | • Medical identity fraud and insurance abuse using health and insurance data | • Identity theft and synthetic identity construction using SSN and DOB | • Targeted phishing and vishing using name, email, and phone | • Doxxing and physical targeting from exposed home addresses | • Discrimination risk from disclosure of substance-use treatment

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
R
Threat Actor: RhysidaConfidence: High
Ransomware-as-a-service group

Motivation: Financial extortion
A ransomware-as-a-service group using double extortion. CISA reporting notes targeting across education, manufacturing, IT, government, and healthcare.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation