The addiction treatment provider has been hit with two attacks, the first which resulted in a lawsuit in 2024.
What happened
American Addiction Centers (AAC), a Brentwood, Tennessee-based provider, has disclosed to the California Attorney General that they recently experienced a data breach involving a third-party vendor. AAC has not yet reported to the Department of Health and Human Services (HHS), but will likely do so in the near future.
In their report to the Attorney General, AAC shared that they learned of suspicious activity on June 5th, 2026, specifically in their Salesforce environment, a software often used to manage customer or patient data and automate daily tasks. After implementing their response protocol, AAC successfully contained the incident and initiated an investigation.
Going deeper
According to the notice, the incident took place on May 12th, when information was acquired by an unknown third party. AAC noted that the incident didn’t involve any direct access to their system, network, or health records application.
Information involved included names, contact information, Social Security numbers, and a brief description provided by patients about their health. AAC specified that this information would have been received through an initial outreach communication from the practice. Currently, there’s no evidence that the information has been misused, but it is always a possibility. AAC is recommending potential victims review statements from their healthcare providers and stay vigilant against fraud or identity theft.
In the know
For AAC, this is their second breach in recent years. Paubox reported on an incident that was only just fully resolved. In September of 2024, AAC had a data breach that impacted 410,747 individuals, with breached information including names, addresses, phone numbers, and medical information. All of the information was ultimately leaked online, allegedly by the threat group Rhysida. The ransomware group emerged in 2023 and remains active, with recent reports stating that they attacked the city of Berlin, Germany. It’s possible that this group is responsible for the most recent attack against AAC, but it isn’t confirmed.
Following the 2024 attack, 12 lawsuits were filed against AAC, which were ultimately consolidated. Nearly two years later, in 2026, a settlement of $2.75 million was reached.
Why it matters
AAC is likely still financially recovering from their last data breach. Outside of the $2.75 million settlement, AAC was also expected to make security improvements and had a myriad of legal fees along the way. While lawsuits like these are designed to hold organizations accountable, they can also be financially devastating, which can be particularly challenging for organizations like treatment centers, which are highly needed, but often underfunded. Ultimately, when an organization like AAC is breached, future patients can be harmed by reductions in services or staff following financial challenges.
The incident also emphasizes that cybersecurity is never completely in a practice’s hands; they are often only as secure as their business partners. However, healthcare practices can and should audit the organizations they work with to ensure that their security standards are high enough to prevent breaches.
FAQs
Is Salesforce HIPAA compliant?
Salesforce can be HIPAA compliant, but is most secure when integrated into a secure environment. For instance, Paubox can be integrated with Salesforce to encrypt all emails containing PHI, which would provide another, robust layer of security.
What does it mean to contain an incident?
Containing an incident generally means that the vulnerability has been fixed and the attacker is no longer an active threat. In this case, Salesforce likely determined that the threat actor was no longer in the environment, and then fixed whatever may have caused the incident (like a stolen password).
Is outreach communication less valuable?
Not necessarily. Many individuals don’t want their communication to addiction or rehabilitation centers made public because of the stigma that can be associated with drug use. However, since the data was more limited, it does mean that less information may have been involved.
