Did Recovery Cafe have a data breach?
Answer
Yes. Recovery Cafe reported a data breach to the Indiana Attorney General on August 6, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- August 6, 2026
- Breach date
- June 26, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Diagnosis and Treatment Information
- Counseling and Progress Notes
- Health Insurance ID Number
- Contact Information
In plain terms
Recovery Cafe in Indiana officially reported a data breach to state regulators in August 2026, following an incident on June 26, 2026. The compromise involved highly sensitive personal and health information for individuals receiving care, prompting concerns about identity and medical privacy.
Recovery Cafe, a community-based wellness and support organization, filed a data breach notification with Indiana authorities on August 6, 2026. The filing indicates that a data security incident occurred on June 26, 2026, impacting individuals who utilize their services.
Organizations like Recovery Cafe, which provide recovery-oriented services and counseling for substance use disorders and mental health challenges, routinely collect and maintain highly sensitive personal and medical information. This includes administrative records, confidential medical histories, mental health assessments, and health insurance details, making them repositories of deeply private data.
According to the official report, the types of information exposed in this breach include Full Name, Date of Birth, Social Security Number, Medical Record Number, Diagnosis and Treatment Information, Counseling and Progress Notes, Health Insurance ID Number, and Contact Information. The nature of the breach itself was not specified in the public filing.
The exposure of such sensitive data carries various risks for affected individuals. This can range from potential identity theft and medical fraud to targeted phishing attempts. Bad actors might leverage compromised identifiers, social security numbers, or medical records to open fraudulent accounts, misuse health insurance benefits, or gain unauthorized access to other personal services.
Individuals who receive a data breach notification from Recovery Cafe should remain vigilant. It is generally recommended to review all financial and medical statements for any unusual activity. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent unauthorized accounts from being opened.
Additionally, be cautious of unsolicited communications that request personal information. These could be phishing attempts using information obtained from the breach. Only respond to legitimate inquiries and verify the sender before providing any data.
This information is based on public disclosures made by Recovery Cafe to regulatory bodies in Indiana. Affected individuals should refer to any official notification letters received directly from Recovery Cafe for specific guidance and details pertaining to their situation.
Other filings by Recovery Cafe
Companies often file the same breach in several states. Each filing is listed separately.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Recovery Cafe.