Bear Mountain Health and Rehabilitation, a skilled nursing facility located on Beaverdam Road in Asheville, North Carolina, has reported a data security incident affecting nearly 1,400 of its patients. The facility, operated by Asheville Beaverdam NC Opco LLC, disclosed the breach to federal regulators as a hacking and IT-related incident.
Nursing homes and other healthcare providers are entrusted with some of the most sensitive information a person has, including medical records, Social Security numbers, and insurance details. When that information is compromised, the facility responsible for safeguarding it may be held accountable.
Bear Mountain Health and Rehabilitation’s Data Breach Investigation
According to a filing with the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR), Asheville Beaverdam NC Opco LLC, doing business as Bear Mountain Health and Rehabilitation, reported a breach of protected health information affecting approximately 1,397 individuals. The facility classified the incident as a Hacking/IT Incident and identified a desktop computer and a network server as the systems involved. The filing also notes that a business associate was present in connection with the incident, meaning a third-party vendor with access to the facility’s systems or data may have played a role in the breach or its discovery.
HHS OCR requires healthcare providers, known as covered entities under HIPAA, to report any breach of unsecured protected health information affecting 500 or more people to the federal government, generally within 60 days of discovering it. The submission alone does not disclose every detail of how the incident occurred, when it was first discovered internally, or what specific investigative steps the facility has taken since. As of this writing, Bear Mountain Health and Rehabilitation has not made a public statement providing further detail beyond what appears in the federal filing.
Skilled nursing facilities and other long-term care providers have increasingly become targets for hacking and ransomware-style attacks in recent years. These facilities often maintain large volumes of highly sensitive data, including medical histories, insurance and billing information, and government-issued identification numbers, while sometimes operating with more limited cybersecurity budgets and staffing than larger hospital systems. That combination of valuable data and comparatively constrained IT resources can make nursing homes and rehabilitation centers attractive targets for cybercriminals seeking to steal or hold data for ransom.
When a hacking incident involves a networked server, as this filing indicates, the exposure can potentially extend beyond a single employee’s workstation to touch a broader set of records stored or accessible on that server. Until Bear Mountain Health and Rehabilitation provides a more detailed public accounting of what data was accessed and how, affected residents, patients, and their families are left to rely on the federal filing and any direct notification letters the facility may send. Individuals who received a breach notification letter, or who otherwise believe their information may have been involved, are encouraged to review any correspondence from the facility carefully and to act quickly to protect their personal and financial information.
Notification of a data breach under HIPAA typically also requires the covered entity to notify affected individuals directly, and in breaches affecting 500 or more residents of a state, to notify prominent media outlets serving that state. Facilities operating in western North Carolina, including those in Buncombe County, are required to follow those same notice provisions regardless of the size of the organization. Following that kind of large-scale disclosure, individuals commonly report an increase in phishing emails, unsolicited phone calls, and other social-engineering attempts by people posing as the healthcare provider, an insurer, or a government agency in an effort to extract additional personal information.
When Did This Breach Occur?
Asheville Beaverdam NC Opco LLC, doing business as Bear Mountain Health and Rehabilitation, submitted its breach report to HHS OCR on July 31, 2026. That submission date reflects when the incident was formally reported to federal regulators, not necessarily the exact date the underlying hacking or IT incident first occurred or was discovered internally. Under HIPAA’s Breach Notification Rule, covered entities generally have up to 60 days from the date they discover a breach to report it to HHS OCR, so the actual intrusion may have taken place at an earlier point in 2026.
As of this writing, Bear Mountain Health and Rehabilitation has not published additional details clarifying the precise date the incident began, when it was detected, or when the facility completed its internal investigation. Affected individuals who receive a direct notification letter from the facility should check that letter for a more specific breach and discovery timeline, since it may include information beyond what appears in the federal filing.
What Information Was Breached?
The HHS OCR filing categorizes the incident as a Hacking/IT Incident involving a desktop computer and a network server, but it does not itemize the specific types of personal or medical information involved. Facilities of this kind typically maintain records that can include residents’ and patients’ names, dates of birth, Social Security numbers, health insurance information, medical record numbers, and clinical or treatment information, though Bear Mountain Health and Rehabilitation has not publicly confirmed which of these categories were affected in this particular incident.
Until the facility discloses a more specific list, affected individuals should assume that any personal or health information they have shared with Bear Mountain Health and Rehabilitation, whether as a resident, a patient, or a family member managing someone else’s care, could potentially have been involved, and should take the protective steps outlined below.
What You Can Do
If you are a current or former resident or patient of Bear Mountain Health and Rehabilitation, or a family member who manages care on someone’s behalf, there are several steps you can take to help protect yourself:
- Watch for a written breach notification letter from Bear Mountain Health and Rehabilitation or Asheville Beaverdam NC Opco LLC, and read it carefully for specific guidance.
- Review your medical bills, insurance statements, and explanation-of-benefits notices for any services or charges you do not recognize.
- Check your credit reports for accounts or inquiries you did not authorize.
- Consider placing a fraud alert or a credit freeze with the three major credit bureaus.
- Be cautious of unsolicited calls, texts, or emails claiming to be from the facility, an insurer, or a government agency asking you to verify personal information.
- Keep any breach notification letter and related records in case you need them later.
File a Data Breach Lawsuit Against Bear Mountain Health and Rehabilitation
If your personal or medical information was compromised as a result of this data breach, you may be entitled to compensation for the harm it caused, including the time and expense of monitoring your accounts and the risk of identity theft or fraud going forward. Nursing homes and other healthcare providers have a legal responsibility to implement reasonable safeguards to protect the sensitive information entrusted to them, and a failure to do so can form the basis of a data breach lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.