Blog > Data Breach & Privacy

Pavillon Data Breach: Data Taken From an Addiction Treatment Center

Pavillon International, a nonprofit addiction treatment center in Mill Spring, North Carolina, says it learned in August 2026 that an unauthorized actor had taken data from its network. Here is what its letters and state filings show, and what current and former patients and employees can do now.

Pavillon Data Breach: Data Taken From an Addiction Treatment Center

What Happened in the Pavillon Data Breach

Suspicious network activity flagged on July 31, 2026

Pavillon International Inc. says it was alerted on July 31, 2026, to suspicious activity inside its computer network. According to its notification letters, dated September 29, the organization moved to secure the network, partnered with outside cybersecurity experts to investigate, and learned on August 7 that an unauthorized actor had accessed portions of the network and taken some data without authorization.

A later review of Pavillon’s servers determined whose information was present and accessible at the time of the incident. Pavillon has not explained how the actor got in. Threat-intelligence firm DeXpose separately reported that a group calling itself Global Secret Group claimed responsibility for an attack on Pavillon on August 5, 2026, in a statement citing 646 GB of files. That claim comes from the group itself, and Pavillon has not attributed the incident to anyone or confirmed it.

What Information May Have Been Involved

Treatment details alongside identity and financial data

Pavillon’s website notice says the affected files generally contained names combined with medical diagnostic or treatment information, health insurance information, and demographic information. The organization’s report to Massachusetts regulators, covering 19 residents of that state, also marks Social Security numbers, financial account information and driver’s license numbers as involved, while marking credit and debit card numbers as not involved. Each letter fills in the specific elements that applied to its recipient, so the mix varies from person to person.

Records from an addiction treatment program can reveal a substance use diagnosis, which many people consider among the most private details of their health history. A federal rule known as 42 CFR Part 2 restricts how many substance use disorder treatment records may be used and disclosed, and the U.S. Department of Health and Human Services keeps a separate public list of breaches involving those records that affect 500 or more people. As of this writing, Pavillon does not appear on that list or on the department’s main HIPAA breach list.

Who May Be Affected by the Pavillon Breach

Current and former patients and employees

Pavillon describes itself as a nonprofit treatment center offering residential and outpatient care for substance use and co-occurring mental health conditions, based in Mill Spring in western North Carolina. Its website notice identifies the people whose information was involved as current and former patients and employees.

The organization has not published a total. The only state figures so far are 19 Massachusetts residents, from that state’s breach report, and three Rhode Island residents, according to the letter. A copy of the letter also appears on the website of South Carolina’s Department of Consumer Affairs, which collects notices when a breach affects more than 1,000 residents of that state, though the posting does not include a count. As of this writing, the incident is not on the breach lists kept by the California, Vermont or Texas attorneys general.

How Pavillon Responded and What It Is Offering

Cyberscout monitoring, with terms that vary by letter

Pavillon’s letter says it reset account passwords, added measures to strengthen its security, reported the incident to federal law enforcement, and continues to review its safeguards, policies and procedures. The letter also states that the notice was not delayed by law enforcement.

Recipients are being offered complimentary credit monitoring and identity protection through Cyberscout, a TransUnion company. The term differs between the versions on file with regulators: the letter posted in South Carolina offers 12 months, while the one filed in Massachusetts offers 24 months. In both versions, enrollment must be completed within 90 days of the September 29 letter date, which works out to December 28, 2026, and the letter notes the service may not be available to anyone under 18.

Steps You Can Take to Protect Yourself

Precautions for treatment center patients and staff

Because treatment details may sit alongside Social Security and financial account numbers, Pavillon patients and employees may want to guard against both medical and financial misuse:

  • Enroll before the 90-day window closes. Use the activation code printed in your own letter, and check whether yours offers 12 or 24 months of coverage.
  • Freeze your credit if your letter lists a Social Security number. A freeze with Equifax, Experian and TransUnion costs nothing and makes it much harder for anyone to open new credit in your name.
  • Read every statement from your health insurer. Explanation of Benefits notices can reveal treatment, prescriptions or claims billed under your name that you never received.
  • Keep an eye on any bank account tied to the financial information in your letter. Unfamiliar withdrawals or new payees can be an early sign that account details are being used.
  • Treat any message about your treatment history as a warning sign. If someone claims to have your records and asks for money or information, do not reply or pay, and keep a copy of the message.

Nothing here is legal advice, and the right next step depends on your own situation. A legal professional can walk you through the rights that may apply to you.

Talk to Wilshire Law Firm

Did you receive a Pavillon data privacy letter?

Were you treated at or employed by Pavillon, and did a letter dated September 29 tell you that your information was involved? Wilshire Law Firm’s nationally recognized, award-winning team includes data privacy attorneys who review incidents like this one, and breaches involving health records and Social Security numbers are often examined as potential class actions. Free consultations and free case reviews with a legal professional are available 24/7, and there are no fees unless you get paid.

Contact Wilshire Law Firm to have your Pavillon letter reviewed confidentially and at no cost.

FAQs

Pavillon says it was alerted to suspicious network activity on July 31, 2026, and learned on August 7, 2026, that an unauthorized actor had accessed parts of its network and taken some data. Its notification letters are dated September 29, 2026.

Yes. Pavillon’s letter states that some data was taken without authorization, and its review found that recipients’ personal information was present and accessible on its servers at the time. The organization also says it has no evidence that anyone’s information has been misused for fraud or identity theft.

Pavillon’s public notice lists names together with medical diagnostic or treatment information, health insurance information, and demographic information. Its Massachusetts filing adds Social Security numbers, financial account information and driver’s license numbers to that list. Your own letter identifies which of these applied to you.

Pavillon has not released a total. Massachusetts’ breach report lists 19 affected residents of that state, and the letter mentions three in Rhode Island, but those state figures are not an overall count.

That depends on your letter. The version posted in South Carolina offers 12 months of Cyberscout credit monitoring and identity protection, and the version filed in Massachusetts offers 24 months. Both require enrollment within 90 days of the September 29, 2026, letter date.

No. Threat-intelligence reporting says Global Secret Group claimed responsibility for an attack on Pavillon on August 5, 2026, in a statement citing 646 GB of data. Pavillon has confirmed that some data was taken, but it has not named any group or addressed the size of that claim.

They may have options. Pavillon’s filings indicate that treatment information, Social Security numbers and financial account details may have been involved for current and former patients and employees, and breaches with that combination of data are frequently reviewed for class action claims. Whether you have a claim depends on what your letter lists and what has happened since, and a free case review can help you sort that out.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,526 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance