Acadia Healthcare email and SharePoint data incident

Unauthorized access to and acquisition of emails and SharePoint files after social engineering compromised one user email account. Patient information contained in the affected email and SharePoint files.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Acadia Healthcare disclosed unauthorized access to and acquisition of emails and SharePoint files after social engineering compromised one user email account. [1]

Impact

Patient information contained in the affected email and SharePoint files. [1][2][3]

Documented data types include:

  • Social Security numbers — For some individuals, a Medicare Health Insurance Claim Number may have included a Social Security number; this does not apply to every affected individual. [1]
  • Dates of birth — The affected information varied by individual. [1]
  • Names — The affected information varied by individual. [1]
  • Health insurance information — The affected information varied by individual. [1]
  • Clinical information — Treatment information, including dates and types of treatment; fields varied by individual. [1]
  • Contact information — Acadia identified addresses among the information involved; fields varied by individual. [1]

A cited record reports 1,807 individuals (Individuals listed for Acadia in the HHS OCR incident portal; treated as a regulator-reported count, not independently verified; as of 2026-08-08). [1][2][3]

A cited record reports 405 individuals (Massachusetts residents listed in incident record 2026-840; this is not a national total; as of 2026-05-22). [1][2][3]

Acadia reported that the incident did not disrupt its operations or its ability to care for patients. [1]

The unauthorized party accessed and acquired certain emails and SharePoint files. [1]

Timeline

  1. Activity began

    Unauthorized access to and acquisition of emails and SharePoint files after social engineering compromised one user email account.

    [1]
  2. Discovery

    Date Acadia detected unusual activity in a user’s email account.

    [1]
  3. Documented activity ended

    End of the access-and-acquisition interval reported by Acadia.

    [1]
  4. Documented event

    Date Acadia says it began notifying patients whose information was involved.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Acadia determined that social engineering was used to gain access to one user email account and its associated SharePoint account. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Acadia secured the email account, engaged a third-party forensic investigation firm, and added safeguards and technical controls. Acadia reported that the incident was limited to one email account and its associated SharePoint account and did not involve its electronic health record systems. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]