Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange County in California has discovered the improper disposal of paper records.
American Addiction Centers, Tennessee
American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services at more than 30 facilities across the United States, has notified the California Attorney General about a recent security incident involving a third-party vendor. According to the notice, suspicious activity was identified within its Salesforce environment on June 5, 2026.
The forensic investigation determined on June 12, 2026, that there had been unauthorized access to its Salesforce instance on May 12, 2026, and data was exfiltrated from that system. The forensic investigation confirmed that the incident did not affect any other systems. The data review confirmed that names, contact information, Social Security numbers, and health insurance information were acquired, along with brief descriptions that patients provided related to their health. The affected data related to initial outreach to American Addiction Centers.
American Addiction Centers said that security measures had been implemented prior to the breach and that it will continue to review its security measures to further protect and monitor its Salesforce environment, and complimentary credit monitoring and identity theft protection services have been made available. At present, it is unclear how many individuals have been affected.
Oculus Pathology, Texas
Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology group that provides services in several U.S. states, has announced an email security incident that has exposed patient information. Suspicious activity was identified within an employee’s email account on April 1, 2026. An investigation was launched to determine the nature and scope of the activity, and it was determined that a small number of employee email accounts had been accessed by an unauthorized third party between March 31, 2026, and April 2, 2026.
Data review specialists were engaged to investigate the incident. Data exposed in the incident includes personally identifiable information such as names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, and individual tax identification numbers. Some financial account numbers and payment card numbers were exposed, in some cases with access information…