Averhealth Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Averhealth data breach, which reportedly may have exposed names, dates of birth, Social Security numbers, driver’s license numbers, electronic signatures, patient account numbers, health insurance policy numbers, medical record numbers, clinical information, diagnoses, medical histories, treatment or procedure information, medical costs, dates of service, provider names, and information concerning a person’s physical or mental condition. Abington Cole + Ellery is investigating potential class action claims.

Published July 15, 2026 | Last updated July 15, 2026
Reviewed by Cornelius P. Dukelow | licensed lawyer and registered patent attorney.

JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Averhealth, please submit your information to be considered:

You may also open the form here: Averhealth Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

Averhealth Data Breach: Key Facts

Company: Averhealth Holdings
Location: Glen Allen, Virginia
Incident Type: unusual activity in email environment
Number Affected: TOTAL NOT YET PUBLICLY CONFIRMED
Data Involved: names, dates of birth, Social Security numbers, driver’s license numbers, electronic signatures, patient account numbers, health insurance policy numbers, medical record numbers, clinical information, diagnoses, medical histories, treatment or procedure information, medical costs, dates of service, provider names, and information concerning a person’s physical or mental condition. Abington Cole + Ellery is investigating potential class action claims
Date Began: December 19, 2025
Date Discovered: January 20, 2026
Date Ended: January 21, 2026
Notice Date: July 2, 2026
Credit Monitoring: 12 Months of Kroll Identity Monitoring
Status: Class Action Lawsuit Investigation


What happened in the Averhealth data breach?

Averhealth Holdings, the parent company of Avertest, Inc., recently disclosed a data security incident involving unauthorized access to Avertest’s email environment and the broader Averhealth network. Averhealth detected unusual email activity on January 20, 2026, contained the activity, and retained outside cybersecurity specialists to investigate. The investigation determined that an unauthorized party had access to the company’s network from December 19, 2025, through January 21, 2026.

Averhealth has not publicly explained exactly how the unauthorized party entered its systems. Its notice does not attribute the incident to phishing, stolen credentials, malware, ransomware, or an exploited software vulnerability. Accordingly, the publicly confirmed explanation is limited to unauthorized activity initially detected in the company’s email environment, followed by evidence that an outside party had accessed its network. The identity of the responsible party also has not been announced.

On May 6, 2026, Averhealth determined that the unauthorized party may have accessed or obtained files containing personal and health information. Depending on the individual, the affected information may have included names, dates of birth, Social Security numbers, driver’s license numbers, electronic signatures, patient account numbers, health insurance policy numbers, medical record numbers, clinical information, diagnoses, medical histories, treatment or procedure information, medical costs, dates of service, provider names, and information concerning a person’s physical or mental condition. Some records may also have identified an individual as a minor. Averhealth emphasized that the same information was not involved for every person.

On or about July 2, 2026, Averhealth began mailing data breach notification letters to potentially affected individuals for whom it had a last known address. The incident was also reported to the Massachusetts Office of Consumer Affairs and Business Regulation on July 7, 2026. As of July 15, 2026, Averhealth has not publicly disclosed the total number of people affected nationwide.

Averhealth states that it has not found evidence that the exposed information has been used for identity theft or financial fraud. Nevertheless, the company recommends that affected individuals review their credit reports, financial accounts, and health insurance explanation-of-benefits statements for unfamiliar activity. Averhealth is offering complimentary credit monitoring to individuals whose Social Security numbers were affected. People with questions or those seeking to determine whether they were involved may call Averhealth’s dedicated response line at 844-959-7153, Monday through Friday from 9:00 a.m. to 6:30 p.m. Eastern Time, excluding holidays.


How did the Averhealth breach occur?

Averhealth has not publicly disclosed the precise cause of the breach. The company detected unusual activity in Avertest’s email environment on January 20, 2026, and later determined that an unauthorized party had accessed its network between December 19, 2025, and January 21, 2026.

Averhealth has not said whether the attacker entered through phishing, stolen login credentials, malware, ransomware, or a software vulnerability. Therefore, the most accurate description is that the incident involved unauthorized access originating in or detected through the company’s email environment, but the specific method remains undisclosed.


When did the Averhealth breach occur?

The Averhealth data breach occurred between December 19, 2025, and January 21, 2026. Averhealth detected unusual activity in Avertest’s email environment on January 20, 2026.


How many people were affected by the Averhealth breach?

The total number of people affected by the Averhealth data breach has not been publicly disclosed. Averhealth’s notice states that it mailed letters to potentially affected individuals beginning around July 2, 2026, but it does not provide a nationwide total.


What information was exposed in the Averhealth breach?

  • The same information was not necessarily involved for every person, but breached data reportedly may include, but is not necessarily limited to:
    • names
    • Social Security number
    • dates of birth
    • driver’s license numbers
    • electronic signatures
    • patient account numbers
    • health insurance policy numbers
    • medical record numbers
    • clinical information
    • diagnoses
    • medical histories
    • treatment or procedure information
    • medical costs
    • dates of service
    • provider names
    • information concerning a person’s physical or mental condition

Has Averhealth offered free credit monitoring and/or identity theft protection services?

Yes. As a result of the data breach, Averhealth is offering 12 months of free identity monitoring through Kroll. The services include: credit monitoring, fraud consultation, and identity-theft restoration.


Averhealth data breach timeline:

Date Event
December 19, 2025 Unauthorized activity began.
January 20, 2026 Averhealth discovered the incident.
January 21, 2026 Unauthorized activity ended.
May of 2026 Data breach investigation concluded.
July 2, 2026 Averhealth began notifying affected individuals.

Who is Averhealth?

Averhealth is a U.S.-based provider of substance use monitoring and drug testing services for courts, probation and parole programs, treatment organizations, and social service agencies. Its services include specimen collection, laboratory testing, randomized test scheduling, and electronic results management through its Aversys platform. Averhealth maintains its national headquarters in Glen Allen, Virginia, and operates a laboratory in Hazelwood, Missouri, testing urine, oral fluid, hair, and sweat samples for a broad range of substances.


What should affected individuals do?

Affected individuals should enroll in the 12 months of complimentary Kroll identity-monitoring services offered by Averhealth before the deadline stated in their notification letter. The services include credit monitoring, fraud consultation, and identity-theft restoration. Individuals should also consider placing a fraud alert or security freeze on their credit files, obtain and review their credit reports, and monitor financial accounts, medical records, and health insurance explanation-of-benefits statements for unfamiliar activity. They should remain cautious of suspicious emails, calls, and text messages and promptly report possible fraud or identity theft to the appropriate financial institution, insurer, law enforcement agency, or the Federal Trade Commission. Anyone with questions may contact Averhealth’s dedicated response line at 844-959-7153.


Averhealth Data Breach Notice

The notice describes the Averhealth data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Averhealth Data Breach Notice in a New Tab


Sources and additional information about the data breach:


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


data types, numbers, timeline, dates



About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Averhealth data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the Averhealth data breach, Averhealth data breach notice, Averhealth class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by Averhealth or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.