Notice of Data Security Incident 

Crossroads Community is committed to protecting the privacy and security of the information in our care. On July 23, 2026, we began mailing notification letters to certain patients whose information was involved in a data security incident. 

We completed an investigation related to an email phishing incident that occurred between March 26, 2026 and April 7, 2026. Crossroads Community employees noticed unusual activity in email accounts and promptly took steps to secure the accounts and third-party experts were engaged to investigate.  

During the unauthorized access to the accounts, various emails were accessed. We performed a review to determine if any of the accessed emails or potentially accessed attachments contained patient’s information. On June 4, 2026, Crossroads Community determined that one or more emails and/or attachments included patient’s names and health insurance member number, Medicare identification number, medication information, and information indicating that you received services at Crossroads Community, such as billed services, provider name, or other details regarding services received. In limited instances, Social Security numbers were also involved and we are providing those patients with credit monitoring.  

We recommend that patients review the statements they receive from their healthcare providers and health insurance plan. If they see any services that were not received, they should contact the provider or health plan immediately.  

We take this matter very seriously. To help prevent something like this from happening again, we have taken steps to enhance our existing security protocols.  

We have set up a designated incident response line to answer patient questions. Patients can call (844) 958-8904, Monday – Friday, 9:00 a.m. to 6:30 p.m. Eastern Time, excluding major U.S. holidays. Please have your membership number ready.