Acadia Healthcare Company Data Breach via Employee Email and SharePoint
Acadia Healthcare Company, Inc.
Key points
- Unusual activity detected in an employee's email account on March 25, 2026.
- Unauthorized access to one email and associated SharePoint account occurred between March 21 and March 25, 2026.
- Initial access gained through social engineering.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
- Published
- Mar 25, 2026
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch phishing, executive impersonation and account-takeover exposure.
- Source type: possible insider or internal misuse
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
Acadia Healthcare Company, Inc. (“Acadia”) experienced a data security incident that involved patient information. This notice explains the incident, measures that have been taken, and some steps patients can take in response. On March 25, 2026, unusual activity was detected in a user’s email account. The email account was secured, and an investigation was launched with the assistance of a third-party forensic investigation firm. Through our investigation, we determined that an unauthorized party gained access to one email account and an associated SharePoint account through social engineering. Between March 21, 2026 and March 25, 2026, the unauthorized party accessed and acquired certain emails and SharePoint files. The investigation confirmed that this incident was limited to the one email account and associated SharePoint account and did not involve our electronic health record systems. Importantly, this incident did not disrupt our operations or our ability to care for patients. A review was initiated to determine the contents of those emails and files involved in the incident. Through this ongoing review, files containing patient information have been identified, including names, addresses, dates of birth, treatment information, dates of treatment, type of treatment, and health insurance information. For some individuals, the files also contained their Medicare Health Insurance Claim Number (HICN), which may include their Social Security number. Beginning on May 22, 2026, notification is being provided to patients whose information was involved in the incident. A dedicated, toll-free incident response line has been established to answer any questions you may have about the incident. If you have any questions, please call 888.500.5708, Monday–Friday, 9:00 am – 9:00 pm Eastern Time, excluding major U.S. holidays. For patients whose information was involved, we recommend that you review any statements you receive from your healthcare providers and health insurance plans. If you see any services that were not received, please contact the provider or health plan immediately. We are committed to protecting the confidentiality and security of the information we maintain. We regret any inconvenience or concern this incident may cause and take this matter seriously. To help prevent something like this from happening again, we have implemented, and will continue to adopt, additional safeguards and technical security measures to further protect and monitor our systems. Data Breaches Announced by Florida Retina Center; Acadia Healthcare Company Florida Retina Center has identified unauthorized access to systems containing the protected health information of more than 13,600 patients. Acadia Healthcare Company has experienced a breach affecting 1,800 patients. Bonita Springs-based Florida Retina Center has announced a cybersecurity incident that was first identified on January 30, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity. On May 19, 2026, Florida Retina Center confirmed unauthorized access to parts of its network containing patient data. The file review confirmed that the data of 13,652 patients was exposed and potentially acquired in the incident. The exposed data included names, dates of birth, Social Security numbers, driver’s license numbers, and medical information. Notification letters have been mailed to the affected individuals, and 12 months of complimentary credit monitoring and identity theft protection services have been made available. At the time of issuing notification letters, no misuse of the affected data had been identified. Franklin, Tennessee-based Acadia Healthcare Company, Inc., a provider of psychiatric and chemical dependency services, has announced a data breach affecting 1,807 individuals. Unusual activity was identified within an employee’s email account on March 25, 2026. The account was secured, and an investigation was launched, which confirmed unauthorized access to a single employee’s email account and associated SharePoint files between March 21, 2026, and March 25, 2026. There was no unauthorized access to any other email accounts, other systems, or the electronic medical record system. Immediate Delivery of Checklist Link To Your Email Address The types of data involved varied from individual to individual, and for the majority of affected individuals, involved one or more of the following data elements in addition to their names: address, date of birth, treatment information, dates of treatment, type of treatment, and health insurance information. Certain individuals also had their Medicare Health Insurance Claim Number (HICN) exposed, which may include their Social Security number. Notification letters were mailed to the affected individuals on May 22, 2026, and additional safeguards have been implemented to prevent similar incidents in the future.
When was this signal reported?
Shadow Tier lists Mar 25, 2026 as the signal date.
Which organization is connected to this signal?
Acadiahealthcare is the organization connected to this public signal.
Explore AcadiahealthcareWhich attack pattern is relevant?
This signal is connected to phishing and social-engineering intelligence based on its reported incident context.
Explore phishing and social-engineering intelligenceWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence