Arrowhead Regional Medical Center (ARMC), operated by San Bernardino County, has notified patients that their personal information may have been exposed in connection with a data security incident affecting Buchalter, LLP, the law firm that provides legal services to ARMC. ARMC worked alongside Buchalter to notify affected individuals of the incident.
Hospitals and the outside firms and vendors they rely on both carry a responsibility to keep patients’ personal information secure, whether that information sits on the hospital’s own systems or with a third party handling matters on the hospital’s behalf.
Arrowhead Regional Medical Center’s Data Breach Investigation
According to the notification letter sent to affected individuals, Buchalter learned on August 28, 2026 that a limited amount of its data was subject to unauthorized acquisition. Buchalter states it immediately took steps to confirm the security of its systems and began an internal investigation with the assistance of third-party computer forensic specialists to evaluate the scope of the incident. Buchalter has said it determined this was an isolated incident and that it has no evidence the unauthorized actor gained access to or impacted its broader network or systems.
Buchalter engaged data mining experts to perform a comprehensive review of the affected data. On September 4, 2026, Buchalter discovered that information belonging to certain ARMC patients was contained within the impacted data set and notified ARMC of that finding. On September 21, 2026, Buchalter secured the information necessary to carry out notice to affected individuals, and ARMC and Buchalter worked together to send notification letters as quickly as possible. Buchalter states it has no evidence that any affected individual’s information has actually been viewed by a third party or misused as a result of the incident.
ARMC has said it promptly began working with Buchalter after learning of the incident to evaluate the breach and its impact on ARMC patients, reviewed Buchalter’s investigation findings, worked to identify which individuals and what information were affected, and coordinated appropriate notification and mitigation efforts.
This incident illustrates a common risk pathway for healthcare organizations: sensitive patient information does not always stay solely within a hospital’s own network. Outside law firms, billing vendors, and other service providers routinely receive patient data in order to carry out work on a healthcare provider’s behalf, and a security incident at any one of those third parties can expose the same patient information a hospital works to protect internally. Regulators generally still hold the healthcare provider responsible for notifying patients even when the underlying incident occurred at a vendor’s systems rather than the provider’s own.
The notification letter Buchalter and ARMC sent describes the specific data elements involved using a placeholder rather than a filled-in list, meaning the exact categories of personal information affected for any given patient have not been made public in a single, universal list. This is not unusual for breach notices tied to a mail-merge template, where the specific per-recipient data fields are inserted individually rather than described the same way for every affected person.
ARMC and Buchalter are offering affected individuals complimentary identity protection services through Experian, including credit monitoring and identity restoration support, at no cost. Patients who receive a notification letter should also be alert to the possibility of follow-up phishing attempts referencing this incident, and should verify any communication using contact information from their own letter or ARMC’s official channels rather than an unsolicited message.
Notification letters that flow through a mail-merge template, like the one Buchalter and ARMC sent here, can leave some fields, such as the exact per-patient list of data elements or the specific number of months of credit monitoring offered, populated individually for each recipient rather than described identically in a single generic paragraph. That is a normal feature of how large-scale breach notification mailings are produced, not a sign that a company is withholding information; the substantive detail is still delivered to each affected person in their own letter, even though a generic sample copy filed with a regulator may show placeholder text where that per-person detail belongs.
Law firms and other professional-services vendors that support hospitals and health systems often hold copies of sensitive records as part of routine legal, billing, or compliance work, meaning a security incident at the vendor’s own systems, rather than the hospital’s, can still put patient information at risk. This kind of third-party or vendor-side exposure has become an increasingly common source of healthcare data breaches, since attackers who cannot easily breach a hospital’s own well-defended network may instead target smaller professional-services firms that hold copies of the same sensitive records with comparatively less security investment.
When Did This Breach Occur?
Buchalter discovered the underlying unauthorized data acquisition on August 28, 2026. It determined on September 4, 2026 that the impacted data included information belonging to ARMC patients, and secured the information necessary to notify affected individuals by September 21, 2026. Notification letters were dated September 28, 2026.
What Information Was Breached?
The notification letter states that the impacted information may have included each affected individual’s name in combination with certain other personal data elements specific to that individual. Buchalter and ARMC have not publicly disclosed a single, universal list of the exact data categories affected across all patients.
What You Can Do
ARMC and Buchalter are offering complimentary identity protection services through Experian IdentityWorks. If you received a notification letter, consider taking these steps:
- Enroll in the complimentary Experian IdentityWorks identity protection services referenced in your notification letter before the enrollment deadline.
- Review your credit and debit card account statements for any unfamiliar activity.
- Consider placing a fraud alert or security freeze on your credit files with the major credit bureaus.
- Contact the dedicated assistance line at 866-566-1941 (Monday through Friday, 6 a.m. to 6 p.m. Pacific Time) with questions about the incident.
File a Data Breach Lawsuit Against Arrowhead Regional Medical Center
If your personal information was exposed in the Arrowhead Regional Medical Center data breach, you may have legal options to pursue compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.