Arizona Vascular Medical Equipment, Inc. Data Breach Exposes Patient and Medical Information

Published: 24 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

A ransomware group called DragonForce claims to have breached Arizona Vascular Medical Equipment, Inc., a Mesa, Arizona medical device supplier, potentially exposing patient and business data. The company has not publicly confirmed the incident or the number of people affected. If you have done business with this company, monitor your credit reports and watch for signs of medical identity theft immediately.

CompanyArizona Vascular Medical Equipment, Inc.
IndustryHealthcare
Data Types ExposedPatient Names and Contact Information, Medical Device Orders and Prescriptions, Health Insurance Information, Billing and Payment Details, Employee Records, Internal Business and Vendor Documents
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Arizona Vascular Medical Equipment Data Breach?

Arizona Vascular Medical Equipment, Inc. is a Mesa-based supplier of compression therapy and vascular care devices. The company serves patients and healthcare providers across the United States. A ransomware group known as DragonForce has claimed responsibility for breaching the company’s network.

According to the claim, DragonForce accessed internal systems and data belonging to Arizona Vascular Medical Equipment. The exact timeline of the intrusion has not been publicly disclosed. As a result, key details about how long the attackers had access remain unknown at this time.

It is important to note that this incident stems from a ransomware group’s own claim of responsibility. Arizona Vascular Medical Equipment has not publicly confirmed the breach as of this writing. Because the company has not issued a statement, there is no confirmed information yet about an internal investigation or forensic review. This article will be updated if the company releases further details.

Who was affected?

The population affected by this incident has not been publicly disclosed. However, given the nature of the company’s business, those potentially impacted likely include patients who purchased or used its medical devices. Employees and business partners could also be affected, since ransomware attacks often expose internal company records alongside customer data.

The exact number of affected individuals has not been publicly disclosed. Because Arizona Vascular Medical Equipment operates nationwide, the geographic scope of this incident could extend well beyond Arizona. It is not yet known whether minors are among those affected, though vascular and mobility equipment providers often serve elderly and medically vulnerable populations who may be particularly susceptible to fraud.

What Information Was Potentially Exposed?

Because Arizona Vascular Medical Equipment has not confirmed the breach, the full scope of exposed data is not yet known. However, based on the nature of the business and the type of information such a company typically stores, the following categories of data may be at risk.

  • Patient names and contact information
  • Medical device orders and prescriptions
  • Health insurance information
  • Billing and payment details
  • Employee records
  • Internal business and vendor documents

If patient or health-related data was in fact compromised, affected individuals could face a heightened risk of medical identity theft. This means someone else could use a person’s identity to obtain medical equipment, services, or insurance benefits. In addition, exposed billing and insurance details could be used to file fraudulent claims.

Beyond medical fraud, exposed contact and personal information could also fuel targeted phishing attempts. For example, scammers often pose as healthcare providers to trick victims into revealing further sensitive details. Because vascular and mobility care patients may include older adults, this population can be especially vulnerable to convincing scam calls or emails.

What is the company doing?

At this time, Arizona Vascular Medical Equipment has not publicly confirmed the breach. Therefore, no official response, investigation, or notification process has been disclosed. This article reflects only the claim made by the DragonForce ransomware group on its leak site.

Because the company has not issued a statement, it remains unclear whether law enforcement has been contacted or whether a forensic investigation is underway. Similarly, no information is currently available regarding credit monitoring or identity protection services being offered to those potentially affected. This article will be updated if Arizona Vascular Medical Equipment releases an official statement or notification.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone who has done business with Arizona Vascular Medical Equipment should consider checking their credit reports regularly. This is a simple, free way to catch unauthorized activity early. You can request free reports from each of the three major credit bureaus once a year at AnnualCreditReport.com.

Because ransomware incidents often involve stolen personal data, monitoring helps you spot new accounts or inquiries you did not authorize. If you notice anything unfamiliar, report it immediately to the credit bureau and consider disputing the entry. Early detection significantly reduces the damage caused by identity theft.

Consider a Fraud Alert or Credit Freeze

If you believe your personal or financial information may have been exposed, placing a fraud alert on your credit file is a strong first step. A fraud alert requires lenders to verify your identity before opening new credit in your name. This can stop identity thieves before they succeed.

For stronger protection, you can also request a credit freeze, which restricts access to your credit file entirely. Although a freeze takes a few extra steps to lift when you need credit, it offers the most reliable defense against new-account fraud. Both options are free and can be requested directly through each credit bureau.

Watch for Signs of Medical Identity Theft

Because this breach involves a medical equipment provider, patients should watch closely for signs of medical identity theft. This includes unfamiliar charges on insurance statements or bills for equipment you never ordered. Reviewing your health insurance explanation of benefits regularly can help you catch this early.

If you spot suspicious activity, contact your insurance provider right away to dispute the charges. You should also request a copy of your medical records to check for inaccuracies caused by fraudulent use of your identity. Correcting these errors quickly can prevent complications with future medical care or insurance coverage.

Stay Alert to Phishing Attempts

Following any data breach, scammers often use stolen contact information to send convincing phishing emails or texts. These messages may impersonate Arizona Vascular Medical Equipment, your insurance company, or even government agencies. Because these scams can look legitimate, it pays to stay cautious.

Never click links or share personal information in response to unsolicited messages. Instead, verify any communication by contacting the company directly using a phone number or website you know is legitimate. If you believe you were targeted, report the attempt to the Federal Trade Commission at reportfraud.ftc.gov.

Consult a Data Breach Attorney

If you have received a notification or believe you were affected by this incident, it may be worth speaking with a data breach attorney. An attorney can help you understand your legal rights and whether you qualify for compensation. Many offer free initial consultations.

Because ransomware incidents involving healthcare data can lead to class action lawsuits, staying informed about your legal options is important. An attorney can also help you monitor for updates about this specific breach. This ensures you do not miss any deadlines if a claims process is later established.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →