Healthcare trio reports Salesforce, email, and trash-bin breaches

New breach notices from an addiction treatment chain, a Texas lab, and a California disability services center span a Salesforce hack, email theft, and misrouted paper records.

MedRisk Staff
By
2 Min Read

Three healthcare organizations have gone public with data incidents ranging from a cloud hack to paper records thrown in the wrong bin.

American Addiction Centers, a Brentwood, Tennessee treatment provider running more than 30 facilities, told the California attorney general that an intruder reached its Salesforce environment on May 12, 2026 and pulled data out before suspicious activity was spotted on June 5. A forensic review pinned the access window and found no other systems touched. Names, contact details, Social Security numbers, health insurance information, and brief health descriptions tied to initial outreach were among the data taken. The affected count has not been disclosed, and credit monitoring is being offered.

Austin, Texas-based Oculus Pathology, an anatomic and clinical pathology group serving several states, found an unauthorized party inside a small number of employee email accounts between March 31 and April 2, 2026, with the activity noticed on April 1. The exposed records include names, birth dates, Social Security numbers, driver’s license and state ID numbers, tax identification numbers, some financial and payment card details, plus clinical information, diagnoses, prescriptions, Medicare numbers, and medical record numbers. The data review is ongoing and no total has been announced.

In a different kind of incident, Regional Center of Orange County, a California nonprofit serving about 29,000 residents with developmental disabilities, reported that a contracted janitorial service tossed paper records into regular trash instead of secure destruction bins on May 27, 2026. The trash was collected before staff could retrieve the documents, so the center notified everyone who received services at its Cypress office. Names, addresses, birth dates, and personal health information were likely exposed.

The notices underscore how patient data can leak through third-party vendors and everyday disposal mistakes, not just sophisticated attacks.

Share This Article