Were you recently affected by a data breach?

SunCloud Health Data Breach

SunCloud Health, a Chicago-area mental health, eating disorder, and addiction treatment provider, reported a data breach to the Illinois Attorney General on June 16, 2026. The filing does not specify what information was compromised. Affected individuals should watch for suspicious activity and contact Class Action U for legal guidance.

SunCloud Health
Date of Breach: Notice reported to the Illinois Attorney General on June 16, 2026 (specific incident date not publicly disclosed)
CAU logo

Who was affected:

Clients of SunCloud Health

Impacted Data:

Not publicly disclosed by SunCloud Health as of this notice; affected individuals should refer to their own notification letter for the specific data types involved.

SunCloud Health provides intensive outpatient, partial hospitalization, and residential treatment for adults and adolescents facing eating disorders, substance use disorders, and co-occurring mental health conditions across several Chicago-area locations. A recent data breach notice filed with the Illinois Attorney General means that current and former patients may have had personal information exposed.

Healthcare providers that manage sensitive medical and behavioral health records carry a heightened responsibility to safeguard that information, and organizations that fail to do so can be held accountable when a breach puts patients at risk.

SunCloud Health’s Data Breach Investigation

SunCloud Health disclosed a data security incident in a notification filed with the Illinois Attorney General’s office on June 16, 2026. The filing itself is limited: it confirms that a breach notice was sent to affected individuals, but it does not specify the date the incident was first discovered, how the exposure occurred, or what specific categories of personal information were involved. As is common with initial regulatory filings, more detailed information about the scope of the breach may only be available in the notification letter mailed directly to those affected.

SunCloud Health operates multiple outpatient and residential treatment centers throughout the Chicago metropolitan area, including locations in Northbrook and Chicago, and serves patients dealing with eating disorders, substance use disorders, and related co-occurring conditions. Because the organization provides clinical behavioral health services, the records it maintains routinely include some of the most sensitive categories of personal data that exist, ranging from psychiatric and substance use treatment histories to insurance and billing information used to coordinate care.

Healthcare and behavioral health providers have become an increasingly frequent target for cybercriminals in recent years. Medical records carry unusually high value on the black market because, unlike a credit card number, they cannot simply be canceled and reissued once compromised. A patient’s diagnosis, treatment history, and insurance identifiers remain sensitive and exploitable indefinitely, which makes healthcare data breaches especially consequential for the people affected by them.

Behavioral health and substance use treatment records carry an additional layer of sensitivity beyond typical medical information. Federal confidentiality protections for substance use disorder treatment records exist specifically because unauthorized disclosure of this information can affect a person’s employment, insurance coverage, housing, and personal relationships. When a treatment provider like SunCloud Health experiences a breach, the potential harm to patients can extend well beyond ordinary identity theft concerns into more personal and lasting consequences.

Regulatory notification requirements, such as those Illinois imposes under 815 ILCS 530/10, are designed to ensure that individuals learn promptly when their personal information has been compromised so they can take protective steps. Companies are required to file notice with the state Attorney General and to send direct notice to affected residents once they determine that unauthorized access to personal information occurred. The exact timeline a company follows between discovering an incident and completing notification can vary based on the nature of the breach and any law enforcement investigation involved, but the law is intended to prevent unreasonable delay.

The notification-law framework that governs incidents like this one typically distinguishes between several separate dates: when a breach actually occurs, when a company first discovers unauthorized activity, and when notice is ultimately sent to affected individuals and regulators. Because SunCloud Health’s public Illinois filing does not spell out all three of those dates, it is not yet possible to say how much time passed between any unauthorized access and the notice that followed. That gap matters to affected patients because it can influence how long their information may have been exposed before protective steps, such as any credit monitoring enrollment deadline, become available to them.

Until SunCloud Health’s own notification letter or a more detailed public filing becomes available, individuals who may have been affected should treat any notice they receive from the organization as the authoritative source for what specifically happened, what information was involved, and what protective resources may be offered. Investigations into the scope and cause of data breaches often continue well after the initial regulatory filing, and companies sometimes provide updated information as more facts become known.

When Did This Breach Occur?

The public filing submitted to the Illinois Attorney General does not state when the underlying security incident was discovered or when it is believed to have occurred. The filing confirms only that SunCloud Health sent breach notification letters with a reported date of June 16, 2026. Companies are generally required to determine the scope of an incident before notifying affected individuals, so the notification date often follows the actual discovery of a breach by some period of time. Anyone who receives a letter directly from SunCloud Health should check it for the specific dates the organization has disclosed, since a mailed notice frequently includes detail that does not appear in the public regulatory filing.

What Information Was Breached?

SunCloud Health’s public filing with the Illinois Attorney General does not identify the specific categories of personal information involved in this incident. Behavioral health providers like SunCloud Health typically maintain records that can include patients’ names, contact information, dates of birth, Social Security numbers, insurance and billing details, and clinical information related to treatment for eating disorders, substance use, or co-occurring mental health conditions. Individuals who received a direct notification letter from SunCloud Health should review it carefully, since the letter mailed to affected patients is the definitive source for which specific data elements applied to their own information.

What You Can Do

If you received a notice from SunCloud Health or believe your information may have been involved in this incident, consider taking the following steps:

  • Read any notification letter carefully and follow the specific instructions it provides.
  • Enroll in any free credit monitoring or identity protection services offered in the notice.
  • Request and review copies of your credit reports from Equifax, Experian, and TransUnion, and consider placing a fraud alert or credit freeze.
  • Monitor insurance statements and explanation-of-benefits notices for unfamiliar medical charges or services.
  • Watch for phishing emails, calls, or texts referencing SunCloud Health or the breach, and never provide personal information in response to an unsolicited message.
  • Keep records of any suspicious activity and report it promptly to your financial institutions and insurer.

File a Data Breach Lawsuit Against SunCloud Health

Patients who trust a treatment provider with sensitive medical and behavioral health information expect that data to be protected. When a company like SunCloud Health experiences a data breach, affected individuals may have legal options to pursue accountability and compensation for the risks created by the exposure of their personal information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 12, 2026 (date claimed by the threat actor; not yet independently confirmed by Cornelius)
Date of Breach: June 8-11, 2026 (discovered June 13, 2026; reported to HHS OCR July 17, 2026)
Date of Breach: Discovered April 23, 2026; publicly disclosed June 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.