American Addiction Centers Discloses Third-Party Salesforce Data Breach Affecting Sensitive Patient Information
American Addiction Centers (AAC) has reported a data breach involving unauthorized access to its Salesforce environment by a third party, exposing personally identifiable and health-related information of individuals who contacted the organization. The incident, detected on June 5, 2026, occurred nearly a month earlier on May 12, 2026, when an attacker accessed sensitive data stored in AAC’s Salesforce instance.
The breach was confirmed by June 8, 2026, following an internal investigation. Exposed data included names, contact details, Social Security numbers, and brief descriptions of health conditions information shared during initial outreach to AAC, such as inquiries about treatment options. The company clarified that the breach did not involve its electronic health records system.
AAC reported the incident to the California Attorney General on August 7, 2026, and began notifying affected individuals by mail. While there is no current evidence of data misuse, the organization is offering complimentary identity protection services through Privacy Solutions ID, including credit monitoring and fraud alerts. Affected individuals must enroll by the deadline specified in their notification letters.
AAC has established a dedicated call center (1-888-650-3763) for breach-related inquiries and directed enrollment support to Epiq (866-675-2006). The breach follows a 2024 incident that impacted 410,000 individuals, underscoring ongoing cybersecurity challenges in the healthcare sector.
Source: https://www.claimdepot.com/data-breach/american-addiction-centers-2026
Salesforce cybersecurity rating report: https://www.rankiteo.com/company/salesforce
"id": "SAL1786285485",
"linkid": "salesforce",
"type": "Breach",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Individuals who contacted AAC '
'for treatment inquiries',
'industry': 'Healthcare',
'location': 'United States',
'name': 'American Addiction Centers (AAC)',
'type': 'Healthcare Organization'}],
'attack_vector': 'Third-party unauthorized access',
'customer_advisories': 'Notification letters mailed to affected individuals '
'with instructions for identity protection services '
'enrollment',
'data_breach': {'personally_identifiable_information': ['Names',
'Contact details',
'Social Security '
'numbers'],
'sensitivity_of_data': 'High (Social Security numbers, health '
'conditions)',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Health-related information']},
'date_detected': '2026-06-05',
'date_publicly_disclosed': '2026-08-07',
'description': 'American Addiction Centers (AAC) has reported a data breach '
'involving unauthorized access to its Salesforce environment '
'by a third party, exposing personally identifiable and '
'health-related information of individuals who contacted the '
'organization. The incident was detected on June 5, 2026, and '
'occurred on May 12, 2026, when an attacker accessed sensitive '
'data stored in AAC’s Salesforce instance. Exposed data '
'included names, contact details, Social Security numbers, and '
'brief descriptions of health conditions shared during initial '
'outreach to AAC. The breach did not involve its electronic '
'health records system.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'sensitive data exposure',
'data_compromised': 'Personally identifiable information (PII) and '
'health-related information',
'identity_theft_risk': 'High (Social Security numbers exposed)',
'legal_liabilities': 'Potential regulatory fines and legal actions',
'systems_affected': 'Salesforce instance'},
'investigation_status': 'Completed (breach confirmed on June 8, 2026)',
'post_incident_analysis': {'root_causes': 'Unauthorized third-party access to '
'Salesforce environment'},
'references': [{'source': 'California Attorney General'}],
'regulatory_compliance': {'regulations_violated': ['Potential HIPAA '
'violations'],
'regulatory_notifications': 'Reported to California '
'Attorney General on '
'August 7, 2026'},
'response': {'communication_strategy': 'Notification letters mailed to '
'affected individuals, dedicated call '
'center (1-888-650-3763), enrollment '
'support (866-675-2006)',
'third_party_assistance': 'Privacy Solutions ID (identity '
'protection services), Epiq '
'(enrollment support)'},
'title': 'American Addiction Centers Discloses Third-Party Salesforce Data '
'Breach Affecting Sensitive Patient Information',
'type': 'Data Breach',
'vulnerability_exploited': 'Salesforce environment misconfiguration/access '
'control'}