American Addiction Centers Data Breach: What Was Exposed and What to Do Next

American Addiction Centers, Inc. sent letters to individuals informing them of a data security incident the company says occurred on or around September 23 through 26, 2024. The letter itself doesn’t spell out exactly how the incident happened or what specific category of records was involved, so the underlying cause is listed as unknown here rather than guessed at. What the company does confirm is that it’s taking the step of offering free credit monitoring, which is usually a signal that the exposed information could include something sensitive enough to warrant that kind of protection, even though the letter provided doesn’t itemize the exact data fields.

Because the version of the notice available doesn’t include a total count of affected individuals, we can’t say precisely how many people received this letter. If you’re reading this because you got one yourself, the notice was addressed to you individually, and it included a unique enrollment code for the credit monitoring service described below — a detail specific to how American Addiction Centers structured this notification rather than something you’d see in every breach letter.

What information does this letter actually say was exposed?
  • The excerpt of the notification made available does not list specific data categories (such as Social Security number, medical record details, or financial account numbers) by name.
  • The company’s decision to offer credit monitoring through Cyberscout suggests the incident may have involved identifiers sensitive enough to carry identity-theft risk, though this isn’t stated outright in the text provided.
  • If your copy of the letter includes a line naming the specific data types affected, that section takes precedence over this summary — check your letter directly for that detail.

American Addiction Centers is offering enrollment in Cyberscout’s credit monitoring service at no cost. To enroll, you’ll need to log on to https://bfs.cyberscout.com/activate and enter the unique code printed in your individual letter, and enrollment must be completed by March 31, 2025.

Steps worth taking if you received this notice
  • Enroll in the free Cyberscout credit monitoring before the March 31, 2025 deadline — once that date passes, the offer may no longer be available.
  • Pull your free credit reports from Equifax, Experian, and TransUnion at AnnualCreditReport.com and look for any accounts or inquiries you don’t recognize.
  • Consider placing a fraud alert or a full security freeze on your credit file with each bureau; a freeze is free and blocks new credit from being opened in your name without your explicit consent.
  • Watch your bank and insurance statements closely for the next several months, since fraud tied to treatment-related or health information can sometimes surface as unusual medical billing rather than typical financial fraud.
  • Since the exact data exposed wasn’t spelled out in the excerpt available, it’s reasonable to treat this cautiously and sign up for a service like Aura or LifeLock, which can flag if your personal details start showing up somewhere they shouldn’t.
  • Keep the letter and your enrollment code somewhere safe in case you need to reference them later when contacting the company or a credit bureau.

If you have questions about this notice, American Addiction Centers can be reached at 1-833-833-2770, Monday through Friday between 8:00 a.m. and 8:00 p.m. Eastern Time.

Leave a Comment