Were you recently affected by a data breach?

Arrowhead Regional Medical Center Data Breach

Arrowhead Regional Medical Center, operated by San Bernardino County, notified patients of a data security incident involving its outside law firm, Buchalter, LLP, that may have exposed personal information tied to their care.

Arrowhead Regional Medical Center
Date of Breach: August 28, 2026
CAU logo

Who was affected:

Clients of Arrowhead Regional Medical Center

Impacted Data:

Names, in combination with other personal data elements specific to each individual (exact universal list not publicly disclosed)

Arrowhead Regional Medical Center (ARMC), operated by San Bernardino County, has notified patients that their personal information may have been exposed in connection with a data security incident affecting Buchalter, LLP, the law firm that provides legal services to ARMC. ARMC worked alongside Buchalter to notify affected individuals of the incident.

Hospitals and the outside firms and vendors they rely on both carry a responsibility to keep patients’ personal information secure, whether that information sits on the hospital’s own systems or with a third party handling matters on the hospital’s behalf.

Arrowhead Regional Medical Center’s Data Breach Investigation

According to the notification letter sent to affected individuals, Buchalter learned on August 28, 2026 that a limited amount of its data was subject to unauthorized acquisition. Buchalter states it immediately took steps to confirm the security of its systems and began an internal investigation with the assistance of third-party computer forensic specialists to evaluate the scope of the incident. Buchalter has said it determined this was an isolated incident and that it has no evidence the unauthorized actor gained access to or impacted its broader network or systems.

Buchalter engaged data mining experts to perform a comprehensive review of the affected data. On September 4, 2026, Buchalter discovered that information belonging to certain ARMC patients was contained within the impacted data set and notified ARMC of that finding. On September 21, 2026, Buchalter secured the information necessary to carry out notice to affected individuals, and ARMC and Buchalter worked together to send notification letters as quickly as possible. Buchalter states it has no evidence that any affected individual’s information has actually been viewed by a third party or misused as a result of the incident.

ARMC has said it promptly began working with Buchalter after learning of the incident to evaluate the breach and its impact on ARMC patients, reviewed Buchalter’s investigation findings, worked to identify which individuals and what information were affected, and coordinated appropriate notification and mitigation efforts.

This incident illustrates a common risk pathway for healthcare organizations: sensitive patient information does not always stay solely within a hospital’s own network. Outside law firms, billing vendors, and other service providers routinely receive patient data in order to carry out work on a healthcare provider’s behalf, and a security incident at any one of those third parties can expose the same patient information a hospital works to protect internally. Regulators generally still hold the healthcare provider responsible for notifying patients even when the underlying incident occurred at a vendor’s systems rather than the provider’s own.

The notification letter Buchalter and ARMC sent describes the specific data elements involved using a placeholder rather than a filled-in list, meaning the exact categories of personal information affected for any given patient have not been made public in a single, universal list. This is not unusual for breach notices tied to a mail-merge template, where the specific per-recipient data fields are inserted individually rather than described the same way for every affected person.

ARMC and Buchalter are offering affected individuals complimentary identity protection services through Experian, including credit monitoring and identity restoration support, at no cost. Patients who receive a notification letter should also be alert to the possibility of follow-up phishing attempts referencing this incident, and should verify any communication using contact information from their own letter or ARMC’s official channels rather than an unsolicited message.

Notification letters that flow through a mail-merge template, like the one Buchalter and ARMC sent here, can leave some fields, such as the exact per-patient list of data elements or the specific number of months of credit monitoring offered, populated individually for each recipient rather than described identically in a single generic paragraph. That is a normal feature of how large-scale breach notification mailings are produced, not a sign that a company is withholding information; the substantive detail is still delivered to each affected person in their own letter, even though a generic sample copy filed with a regulator may show placeholder text where that per-person detail belongs.

Law firms and other professional-services vendors that support hospitals and health systems often hold copies of sensitive records as part of routine legal, billing, or compliance work, meaning a security incident at the vendor’s own systems, rather than the hospital’s, can still put patient information at risk. This kind of third-party or vendor-side exposure has become an increasingly common source of healthcare data breaches, since attackers who cannot easily breach a hospital’s own well-defended network may instead target smaller professional-services firms that hold copies of the same sensitive records with comparatively less security investment.

When Did This Breach Occur?

Buchalter discovered the underlying unauthorized data acquisition on August 28, 2026. It determined on September 4, 2026 that the impacted data included information belonging to ARMC patients, and secured the information necessary to notify affected individuals by September 21, 2026. Notification letters were dated September 28, 2026.

What Information Was Breached?

The notification letter states that the impacted information may have included each affected individual’s name in combination with certain other personal data elements specific to that individual. Buchalter and ARMC have not publicly disclosed a single, universal list of the exact data categories affected across all patients.

What You Can Do

ARMC and Buchalter are offering complimentary identity protection services through Experian IdentityWorks. If you received a notification letter, consider taking these steps:

  • Enroll in the complimentary Experian IdentityWorks identity protection services referenced in your notification letter before the enrollment deadline.
  • Review your credit and debit card account statements for any unfamiliar activity.
  • Consider placing a fraud alert or security freeze on your credit files with the major credit bureaus.
  • Contact the dedicated assistance line at 866-566-1941 (Monday through Friday, 6 a.m. to 6 p.m. Pacific Time) with questions about the incident.

File a Data Breach Lawsuit Against Arrowhead Regional Medical Center

If your personal information was exposed in the Arrowhead Regional Medical Center data breach, you may have legal options to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 28, 2026
Date of Breach: Not publicly disclosed
Date of Breach: June 1, 2026 to July 27, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.