Were you recently affected by a data breach?

Bear Mountain Health and Rehabilitation Data Breach

Bear Mountain Health and Rehabilitation, a skilled nursing facility in Asheville, North Carolina, reported a hacking/IT security incident to federal regulators that may have compromised the personal information of 1,397 residents and patients. Affected individuals may be entitled to compensation through a data breach lawsuit.

Bear Mountain Health and Rehabilitation
Date of Breach: Reported to HHS OCR on July 31, 2026 (exact incident date not publicly disclosed)
CAU logo

Who was affected:

Clients of Bear Mountain Health and Rehabilitation

Impacted Data:

Names, dates of birth, Social Security numbers, health insurance information, medical record numbers, and other protected health information (specific categories not yet publicly disclosed)

Bear Mountain Health and Rehabilitation, a skilled nursing facility located on Beaverdam Road in Asheville, North Carolina, has reported a data security incident affecting nearly 1,400 of its patients. The facility, operated by Asheville Beaverdam NC Opco LLC, disclosed the breach to federal regulators as a hacking and IT-related incident.

Nursing homes and other healthcare providers are entrusted with some of the most sensitive information a person has, including medical records, Social Security numbers, and insurance details. When that information is compromised, the facility responsible for safeguarding it may be held accountable.

Bear Mountain Health and Rehabilitation’s Data Breach Investigation

According to a filing with the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR), Asheville Beaverdam NC Opco LLC, doing business as Bear Mountain Health and Rehabilitation, reported a breach of protected health information affecting approximately 1,397 individuals. The facility classified the incident as a Hacking/IT Incident and identified a desktop computer and a network server as the systems involved. The filing also notes that a business associate was present in connection with the incident, meaning a third-party vendor with access to the facility’s systems or data may have played a role in the breach or its discovery.

HHS OCR requires healthcare providers, known as covered entities under HIPAA, to report any breach of unsecured protected health information affecting 500 or more people to the federal government, generally within 60 days of discovering it. The submission alone does not disclose every detail of how the incident occurred, when it was first discovered internally, or what specific investigative steps the facility has taken since. As of this writing, Bear Mountain Health and Rehabilitation has not made a public statement providing further detail beyond what appears in the federal filing.

Skilled nursing facilities and other long-term care providers have increasingly become targets for hacking and ransomware-style attacks in recent years. These facilities often maintain large volumes of highly sensitive data, including medical histories, insurance and billing information, and government-issued identification numbers, while sometimes operating with more limited cybersecurity budgets and staffing than larger hospital systems. That combination of valuable data and comparatively constrained IT resources can make nursing homes and rehabilitation centers attractive targets for cybercriminals seeking to steal or hold data for ransom.

When a hacking incident involves a networked server, as this filing indicates, the exposure can potentially extend beyond a single employee’s workstation to touch a broader set of records stored or accessible on that server. Until Bear Mountain Health and Rehabilitation provides a more detailed public accounting of what data was accessed and how, affected residents, patients, and their families are left to rely on the federal filing and any direct notification letters the facility may send. Individuals who received a breach notification letter, or who otherwise believe their information may have been involved, are encouraged to review any correspondence from the facility carefully and to act quickly to protect their personal and financial information.

Notification of a data breach under HIPAA typically also requires the covered entity to notify affected individuals directly, and in breaches affecting 500 or more residents of a state, to notify prominent media outlets serving that state. Facilities operating in western North Carolina, including those in Buncombe County, are required to follow those same notice provisions regardless of the size of the organization. Following that kind of large-scale disclosure, individuals commonly report an increase in phishing emails, unsolicited phone calls, and other social-engineering attempts by people posing as the healthcare provider, an insurer, or a government agency in an effort to extract additional personal information.

When Did This Breach Occur?

Asheville Beaverdam NC Opco LLC, doing business as Bear Mountain Health and Rehabilitation, submitted its breach report to HHS OCR on July 31, 2026. That submission date reflects when the incident was formally reported to federal regulators, not necessarily the exact date the underlying hacking or IT incident first occurred or was discovered internally. Under HIPAA’s Breach Notification Rule, covered entities generally have up to 60 days from the date they discover a breach to report it to HHS OCR, so the actual intrusion may have taken place at an earlier point in 2026.

As of this writing, Bear Mountain Health and Rehabilitation has not published additional details clarifying the precise date the incident began, when it was detected, or when the facility completed its internal investigation. Affected individuals who receive a direct notification letter from the facility should check that letter for a more specific breach and discovery timeline, since it may include information beyond what appears in the federal filing.

What Information Was Breached?

The HHS OCR filing categorizes the incident as a Hacking/IT Incident involving a desktop computer and a network server, but it does not itemize the specific types of personal or medical information involved. Facilities of this kind typically maintain records that can include residents’ and patients’ names, dates of birth, Social Security numbers, health insurance information, medical record numbers, and clinical or treatment information, though Bear Mountain Health and Rehabilitation has not publicly confirmed which of these categories were affected in this particular incident.

Until the facility discloses a more specific list, affected individuals should assume that any personal or health information they have shared with Bear Mountain Health and Rehabilitation, whether as a resident, a patient, or a family member managing someone else’s care, could potentially have been involved, and should take the protective steps outlined below.

What You Can Do

If you are a current or former resident or patient of Bear Mountain Health and Rehabilitation, or a family member who manages care on someone’s behalf, there are several steps you can take to help protect yourself:

  • Watch for a written breach notification letter from Bear Mountain Health and Rehabilitation or Asheville Beaverdam NC Opco LLC, and read it carefully for specific guidance.
  • Review your medical bills, insurance statements, and explanation-of-benefits notices for any services or charges you do not recognize.
  • Check your credit reports for accounts or inquiries you did not authorize.
  • Consider placing a fraud alert or a credit freeze with the three major credit bureaus.
  • Be cautious of unsolicited calls, texts, or emails claiming to be from the facility, an insurer, or a government agency asking you to verify personal information.
  • Keep any breach notification letter and related records in case you need them later.

File a Data Breach Lawsuit Against Bear Mountain Health and Rehabilitation

If your personal or medical information was compromised as a result of this data breach, you may be entitled to compensation for the harm it caused, including the time and expense of monitoring your accounts and the risk of identity theft or fraud going forward. Nursing homes and other healthcare providers have a legal responsibility to implement reasonable safeguards to protect the sensitive information entrusted to them, and a failure to do so can form the basis of a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Billing statements dated May 16, 2026; discovered by LCHD/CHC on May 22, 2026
Date of Breach: Reported to HHS OCR on July 31, 2026 (exact incident date not publicly disclosed)
Date of Breach: Claimed August 18, 2026 (unconfirmed by the practice)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.