The American Addiction Centers (AAC) data breach affected 422,424 people according to a later state filing reported by SecurityWeek. The incident occurred September 23–26, 2024, and involved sensitive personal and health-related identifiers, including Social Security numbers. AAC said it notified potentially affected patients in November and December 2024.
How many people were affected by the AAC data breach?
The later figure was 422,424 people, listed in AAC’s December 23, 2024 notice to Maine, as reported by SecurityWeek. An earlier filing to the U.S. Department of Health and Human Services listed 410,747 people. The often-rounded figure of 422,000 refers to the later, larger count—not the only number reported.
When did the breach happen?
| Date | What happened |
|---|---|
| September 23–26, 2024 | California’s submitted notice lists this as the breach period. |
| On or about September 26, 2024 | AAC and the settlement materials describe unauthorized access to or acquisition of information around this date. |
| November–December 2024 | AAC said it notified potentially affected patients. |
SecurityWeek reported that the Rhysida ransomware group claimed responsibility and said it had stolen roughly 2.8 terabytes of data. The official AAC and settlement materials do not definitively attribute the incident to that group, so Rhysida should be described as a reported claimant, not a confirmed perpetrator.
What information did the AAC breach expose?
Reported information categories included names, addresses, phone numbers, dates of birth, Social Security numbers, health-insurance information, medical-record numbers, and other identifiers. AAC’s notice said the affected information did not include treatment information or payment-card data. Settlement materials describe allegations that include treatment information; that allegation should not be treated as an uncontested description of the information in every affected person’s file.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
So, yes: Social Security numbers were among the categories reported as potentially affected. That does not establish that every person’s Social Security number was involved. If you received a breach letter, use it to determine which specific information AAC identified for you.
What to do if you received an AAC breach letter
- Read the letter for the affected data types. Check whether it identifies your Social Security number, insurance information, medical-record number, or other information as involved.
- Use the identity-monitoring offer described in the notice. Follow the enrollment instructions and keep a copy of the letter and enrollment details.
- Review accounts and credit reports. AAC advised recipients to regularly review account statements and free credit reports, and to report suspicious account activity promptly to their banks and other financial institutions.
- Consider a fraud alert or security freeze. The notice directed recipients to these options. A fraud alert asks creditors to take additional steps to verify identity; a freeze restricts access to a credit file. The appropriate choice depends on how quickly you want protection and whether you may need to apply for credit.
- Keep records of related expenses. If you seek reimbursement under the settlement, retain receipts and other documentation for expenses you believe resulted from the incident.
AAC’s notice said it had no evidence at that time that anyone’s information had been used for identity theft or fraud. That statement describes what AAC reported when issuing the notice; it is not a guarantee that misuse cannot occur.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the settlement provides—and what its deadlines mean
The case is In re American Addiction Centers, Inc. Data Breach Litigation, No. 3:24-cv-01505, in the U.S. District Court for the Middle District of Tennessee. The settlement materials say AAC denies the plaintiffs’ allegations. A settlement is not a finding that the allegations were proven.
| Settlement item | What the FAQ says |
|---|---|
| Credit monitoring and identity-theft protection | Two years for participating claimants. |
| Documented expense reimbursement | Up to $5,000 for documented expenses, subject to the settlement terms. |
| Cash payment | An estimated $50 pro-rata payment; the final amount depends on the settlement process and number of valid claims. |
The settlement FAQ listed March 6, 2026 as the deadline to opt out or object, March 23, 2026 as the claim deadline, and April 20, 2026 as the scheduled final-approval hearing. Those dates have passed. The FAQ says benefits follow final approval and resolution of any challenges, but it does not establish a payment date. Without a later official status update, it is not possible to say whether claims have reopened, when payments will be sent, or whether the settlement has completed the remaining steps.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
If you want to check whether the administrator has posted a later update, use the official settlement site or contact information on a notice you received. The listed claim deadline has passed, so do not assume a new claim can be filed unless the administrator confirms that the process has changed.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

