Data Breach & Privacy
Blog > Data Breach & Privacy
Pavillon Data Breach: Data Taken From an Addiction Treatment Center
Pavillon International, a nonprofit addiction treatment center in Mill Spring, North Carolina, says it learned in August 2026 that an unauthorized actor had taken data from its network. Here is what its letters and state filings show, and what current and former patients and employees can do now.

What Happened in the Pavillon Data Breach
Suspicious network activity flagged on July 31, 2026
Pavillon International Inc. says it was alerted on July 31, 2026, to suspicious activity inside its computer network. According to its notification letters, dated September 29, the organization moved to secure the network, partnered with outside cybersecurity experts to investigate, and learned on August 7 that an unauthorized actor had accessed portions of the network and taken some data without authorization.
A later review of Pavillon’s servers determined whose information was present and accessible at the time of the incident. Pavillon has not explained how the actor got in. Threat-intelligence firm DeXpose separately reported that a group calling itself Global Secret Group claimed responsibility for an attack on Pavillon on August 5, 2026, in a statement citing 646 GB of files. That claim comes from the group itself, and Pavillon has not attributed the incident to anyone or confirmed it.
What Information May Have Been Involved
Treatment details alongside identity and financial data
Pavillon’s website notice says the affected files generally contained names combined with medical diagnostic or treatment information, health insurance information, and demographic information. The organization’s report to Massachusetts regulators, covering 19 residents of that state, also marks Social Security numbers, financial account information and driver’s license numbers as involved, while marking credit and debit card numbers as not involved. Each letter fills in the specific elements that applied to its recipient, so the mix varies from person to person.
Records from an addiction treatment program can reveal a substance use diagnosis, which many people consider among the most private details of their health history. A federal rule known as 42 CFR Part 2 restricts how many substance use disorder treatment records may be used and disclosed, and the U.S. Department of Health and Human Services keeps a separate public list of breaches involving those records that affect 500 or more people. As of this writing, Pavillon does not appear on that list or on the department’s main HIPAA breach list.
Who May Be Affected by the Pavillon Breach
Current and former patients and employees
Pavillon describes itself as a nonprofit treatment center offering residential and outpatient care for substance use and co-occurring mental health conditions, based in Mill Spring in western North Carolina. Its website notice identifies the people whose information was involved as current and former patients and employees.
The organization has not published a total. The only state figures so far are 19 Massachusetts residents, from that state’s breach report, and three Rhode Island residents, according to the letter. A copy of the letter also appears on the website of South Carolina’s Department of Consumer Affairs, which collects notices when a breach affects more than 1,000 residents of that state, though the posting does not include a count. As of this writing, the incident is not on the breach lists kept by the California, Vermont or Texas attorneys general.
How Pavillon Responded and What It Is Offering
Cyberscout monitoring, with terms that vary by letter
Pavillon’s letter says it reset account passwords, added measures to strengthen its security, reported the incident to federal law enforcement, and continues to review its safeguards, policies and procedures. The letter also states that the notice was not delayed by law enforcement.
Recipients are being offered complimentary credit monitoring and identity protection through Cyberscout, a TransUnion company. The term differs between the versions on file with regulators: the letter posted in South Carolina offers 12 months, while the one filed in Massachusetts offers 24 months. In both versions, enrollment must be completed within 90 days of the September 29 letter date, which works out to December 28, 2026, and the letter notes the service may not be available to anyone under 18.
Steps You Can Take to Protect Yourself
Precautions for treatment center patients and staff
Because treatment details may sit alongside Social Security and financial account numbers, Pavillon patients and employees may want to guard against both medical and financial misuse:
- Enroll before the 90-day window closes. Use the activation code printed in your own letter, and check whether yours offers 12 or 24 months of coverage.
- Freeze your credit if your letter lists a Social Security number. A freeze with Equifax, Experian and TransUnion costs nothing and makes it much harder for anyone to open new credit in your name.
- Read every statement from your health insurer. Explanation of Benefits notices can reveal treatment, prescriptions or claims billed under your name that you never received.
- Keep an eye on any bank account tied to the financial information in your letter. Unfamiliar withdrawals or new payees can be an early sign that account details are being used.
- Treat any message about your treatment history as a warning sign. If someone claims to have your records and asks for money or information, do not reply or pay, and keep a copy of the message.
Nothing here is legal advice, and the right next step depends on your own situation. A legal professional can walk you through the rights that may apply to you.
Talk to Wilshire Law Firm
Did you receive a Pavillon data privacy letter?
Were you treated at or employed by Pavillon, and did a letter dated September 29 tell you that your information was involved? Wilshire Law Firm’s nationally recognized, award-winning team includes data privacy attorneys who review incidents like this one, and breaches involving health records and Social Security numbers are often examined as potential class actions. Free consultations and free case reviews with a legal professional are available 24/7, and there are no fees unless you get paid.
Contact Wilshire Law Firm to have your Pavillon letter reviewed confidentially and at no cost.
FAQs
Pavillon says it was alerted to suspicious network activity on July 31, 2026, and learned on August 7, 2026, that an unauthorized actor had accessed parts of its network and taken some data. Its notification letters are dated September 29, 2026.
Yes. Pavillon’s letter states that some data was taken without authorization, and its review found that recipients’ personal information was present and accessible on its servers at the time. The organization also says it has no evidence that anyone’s information has been misused for fraud or identity theft.
Pavillon’s public notice lists names together with medical diagnostic or treatment information, health insurance information, and demographic information. Its Massachusetts filing adds Social Security numbers, financial account information and driver’s license numbers to that list. Your own letter identifies which of these applied to you.
Pavillon has not released a total. Massachusetts’ breach report lists 19 affected residents of that state, and the letter mentions three in Rhode Island, but those state figures are not an overall count.
That depends on your letter. The version posted in South Carolina offers 12 months of Cyberscout credit monitoring and identity protection, and the version filed in Massachusetts offers 24 months. Both require enrollment within 90 days of the September 29, 2026, letter date.
No. Threat-intelligence reporting says Global Secret Group claimed responsibility for an attack on Pavillon on August 5, 2026, in a statement citing 646 GB of data. Pavillon has confirmed that some data was taken, but it has not named any group or addressed the size of that claim.
They may have options. Pavillon’s filings indicate that treatment information, Social Security numbers and financial account details may have been involved for current and former patients and employees, and breaches with that combination of data are frequently reviewed for class action claims. Whether you have a claim depends on what your letter lists and what has happened since, and a free case review can help you sort that out.

