Raise the Bottom 2026 Data Breach: Addiction-Treatment Patient Data Exposed
Idaho opioid and addiction treatment provider.
Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly.
Breach Risk Index i
100/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
58k rowsRecords
2026Year
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In 2026 (reported May 15) Raise the Bottom disclosed a data breach exposing patient information; the incident affected roughly 58,000 individuals with exposed data including names, substance-use/behavioral-health information and Social Security numbers.
Full threat analysis, exploitation vectors, and principal guidance below.
9 additional sections · verified field analysis · defensive doctrine
Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…
58k rows records analyzed
About Raise the Bottom
Raise the Bottom is an Idaho addiction-treatment provider operating opioid and substance-use treatment and counseling services across multiple locations.
Why They Hold Your Data
An addiction-treatment provider holds patient identity and contact data, SSNs, and highly sensitive substance-use and behavioral-health treatment records protected under 42 CFR Part 2 and HIPAA.
Recent Developments
The provider disclosed a breach reported May 15, 2026, with scope still being determined.
Data Points Exposed
3 verified field types
Full Name
Medical Diagnosis (behavioral health) Critical
Social Security Number Critical
Breach Impact
As a 42 CFR Part 2 provider, the breach carries heightened confidentiality obligations and acute patient-trust and stigma concerns.
Principal Risk Advisory
What this means for a principal
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
What You Should Do
Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.
How ObscureIQ Can Help
Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
Protect Yourself
High-Risk? Get an Exposure Audit
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.