Were you recently affected by a data breach?

Arkansas Oral & Maxillofacial Surgeons Data Breach

Arkansas Oral & Maxillofacial Surgeons, based in Hot Springs, Arkansas, discovered in June 2026 that an unauthorized third party accessed patient files containing names, Social Security numbers, treatment records, and health insurance information. Affected patients are being offered complimentary credit and health information monitoring.

Arkansas Oral & Maxillofacial Surgeons
Date of Breach: Unauthorized access discovered April 7, 2026; confirmed June 2, 2026
CAU logo

Who was affected:

Clients of Arkansas Oral & Maxillofacial Surgeons

Impacted Data:

Names, contact information, dates of birth, treatment records, prescription history, payment information, diagnosis information, medical record numbers, health insurance information, Social Security numbers

Arkansas Oral & Maxillofacial Surgeons, a dental surgery practice based in Hot Springs, Arkansas, recently notified patients that their personal and health information may have been exposed after an unauthorized party gained access to the practice’s computer systems. Healthcare providers that collect detailed medical and financial records have a responsibility to protect that information, and patients affected by this kind of exposure deserve a clear explanation of what happened and what they can do next.

Arkansas Oral & Maxillofacial Surgeons’s Data Breach Investigation

Arkansas Oral & Maxillofacial Surgeons, legally organized as A-O-M-S, P.L.L.C., operates as an oral and maxillofacial surgery practice with a location at 200 McAuley Court in Hot Springs, Arkansas. According to the practice’s notification letter, it first learned of potential unauthorized access to its computer systems on April 7, 2026. AOMS launched an investigation immediately, and on June 2, 2026, that investigation determined that an unauthorized third party had acquired files containing patient information.

Separately, a threat-intelligence report identified a ransomware group calling itself “Pear” as having claimed responsibility for an attack on AOMS around April 10, 2026, threatening to publish stolen patient data if the practice did not respond to its demands. AOMS’s own notification letter to patients does not name any specific threat actor or confirm whether a ransom demand was made, which is common when a company is still working with law enforcement or negotiating during an active incident.

The roughly two-month gap between AOMS’s initial discovery of unauthorized access in April and its confirmation in June that patient files had actually been taken reflects a typical forensic investigation timeline for this type of incident. Determining not just that a network was accessed, but specifically which files were viewed or copied and which individuals are affected, often requires a detailed forensic review of system logs, an especially involved process for smaller healthcare practices that may not have extensive built-in monitoring tools.

Medical practices are a persistent target for ransomware and data-theft groups because patient records combine highly sensitive personal identifiers, such as Social Security numbers and dates of birth, with equally sensitive health and insurance information in a single file. This combination is especially valuable to criminals because it can be used not only for conventional identity theft and new-account fraud, but also for medical identity theft, where a stolen identity is used to obtain healthcare services or prescriptions billed to someone else’s insurance.

AOMS stated in its notification letter that it took immediate steps upon discovering the unauthorized activity to investigate, stop any ongoing unauthorized access, and further secure its systems. The practice is offering affected patients complimentary credit monitoring, health information monitoring, and identity theft protection services through CyEx’s Medical Shield program. Patients who received a letter with a specific activation code should enroll before the deadline listed in their individual notice, since these enrollment windows typically expire a set number of months after the letter date and are not automatically extended.

When Did This Breach Occur?

AOMS states it first discovered potential unauthorized access to its systems on April 7, 2026, and confirmed on June 2, 2026, following an investigation, that patient files had been accessed by an unauthorized third party. A ransomware group calling itself Pear reportedly claimed responsibility for an attack on the practice around April 10, 2026.

What Information Was Breached?

AOMS’s investigation identified that the following types of information may have been involved for at least some patients: names, contact information, dates of birth, treatment records, prescription history, payment information, diagnosis information, medical record numbers, health insurance information, and government identification numbers, including Social Security numbers. Not every category was necessarily exposed for every affected individual.

What You Can Do

If you received a letter from Arkansas Oral & Maxillofacial Surgeons, consider taking the following steps:

  • Enroll in the complimentary CyEx Medical Shield credit and health information monitoring referenced in your letter before the enrollment deadline.
  • Monitor your financial accounts and health insurance explanation-of-benefits statements for unauthorized activity.
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
  • Request a free copy of your credit report at annualcreditreport.com to check for unfamiliar accounts.
  • Remain alert for phishing attempts referencing this breach, and verify the identity of anyone requesting your personal information before responding.

File a Data Breach Lawsuit Against Arkansas Oral & Maxillofacial Surgeons

If you received a data breach notification letter from Arkansas Oral & Maxillofacial Surgeons, you may have legal options available to you. Healthcare providers are expected to maintain reasonable safeguards to protect patients’ sensitive personal and medical information, and individuals affected by a breach may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Underlying vendor incident occurred May 29 - June 1, 2026; New Era notified employees in 2026
Date of Breach: Incident occurred July 8, 2026; Oregon notification filed August 5, 2026
Date of Breach: Hacker group's claim of responsibility posted on or around August 5, 2026; not yet confirmed by the company
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.