Arrowhead Regional Medical Center Data Breach Exposes Patient Health Information

Published: 29 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Arrowhead Regional Medical Center, operated by San Bernardino County, notified California regulators in September 2026 of a data breach involving patient information. The exact number of affected individuals and the specific data exposed have not been fully disclosed. Patients should monitor credit reports and insurance statements closely, and consider a credit freeze to guard against identity theft.

CompanyArrowhead Regional Medical Center
IndustryHealthcare
Data Types ExposedPatient Names, Medical Treatment Information, Health Insurance Details, Dates of Birth, Contact Information, Medical Record Numbers
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedCalifornia Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Arrowhead Regional Medical Center Data Breach?

San Bernardino County, acting on behalf of Arrowhead Regional Medical Center, has disclosed a data breach affecting patients of the facility. The county filed a formal notification with the California Attorney General’s office in September 2026. This filing confirms that patient information was involved in a security event at the medical center.

The Arrowhead Regional Medical Center data breach notification does not specify the exact date the intrusion or exposure occurred. As a result, the breach discovery date has not been publicly disclosed. What is confirmed is that the county considered the incident serious enough to warrant formal notice to regulators and, presumably, to affected patients.

Details about the specific attack method have not been made public in the filing. Because this notification comes through an official government channel, it represents a confirmed disclosure rather than an unverified claim. However, deeper forensic specifics, such as how attackers may have gained access or how long the exposure lasted, remain undisclosed at this time.

Medical centers like Arrowhead Regional often maintain large volumes of sensitive patient data. This makes them frequent targets for cybercriminals. When a breach like this happens, the investigation process typically includes forensic review, legal consultation, and notification procedures required under both state and federal law.

Who was affected?

The individuals affected by this breach are patients who received care or services through Arrowhead Regional Medical Center. Because this is a county-operated medical facility, the population affected likely includes residents of San Bernardino County and possibly patients from surrounding areas in Southern California.

The exact number of affected individuals has not been publicly disclosed. This is common in early breach filings, where the scope may still be under investigation. Therefore, the recordsAffectedText for this incident should be considered Not Publicly Disclosed until further information becomes available.

Given that this is a medical facility, the affected population could include people of all ages, including minors who received pediatric care. In addition, hospital breaches often affect not just patients but also potentially their emergency contacts or guarantors listed in medical records.

Because Arrowhead Regional Medical Center serves a broad community, the breach could touch a wide demographic. This includes both insured and uninsured patients who accessed emergency, inpatient, or outpatient services at the facility.

What Information Was Potentially Exposed?

While the full scope of exposed data categories has not been detailed publicly, breaches at medical facilities typically involve sensitive personal and health-related information. Based on the nature of the notification and the type of institution involved, the following categories of information are commonly at risk in incidents like this one.

  • Patient names
  • Medical treatment information
  • Health insurance details
  • Dates of birth
  • Contact information
  • Medical record numbers

Because this notification stems from a healthcare provider, any exposed data could include protected health information under HIPAA. This type of data is especially sensitive because it reveals private medical history. Unlike a password, medical details cannot simply be changed after a breach.

If attackers gained access to this information, patients could face risks beyond typical identity theft. For example, criminals could use stolen medical details to commit healthcare fraud. This might involve filing false insurance claims or obtaining medical services under a victim’s identity.

In addition, exposed contact and demographic information could be used for targeted phishing attempts. Scammers often pose as healthcare providers or insurers to trick victims into revealing more sensitive data, such as Social Security numbers or payment information. This makes vigilance especially important for anyone notified of this breach.

What is the company doing?

San Bernardino County, on behalf of Arrowhead Regional Medical Center, filed a formal notification with the California Attorney General in September 2026. This filing represents an official acknowledgment of the incident and a legal step required under California’s data breach notification laws.

Beyond the regulatory filing itself, specific remediation steps taken by the medical center have not been detailed in available public records. Typically, healthcare organizations facing a breach of this kind conduct internal investigations, work with cybersecurity specialists, and coordinate with legal counsel to determine the appropriate response.

Because this is a government-affiliated medical facility, additional oversight may come from county administrators or state health agencies. As more information becomes available, affected patients may receive direct notification letters outlining any protective services offered, such as credit monitoring or identity theft protection.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to Arrowhead Regional Medical Center should regularly check their credit reports for unfamiliar activity. This includes new account openings, unexpected credit inquiries, or unfamiliar charges. Because medical identity theft can sometimes overlap with financial fraud, credit monitoring remains an important defensive step.

You can request free credit reports from all three major credit bureaus through annualcreditreport.com. Reviewing these reports every few months, rather than just once, helps catch suspicious activity early. If you notice anything unusual, report it immediately to the credit bureau and consider filing a fraud alert.

Watch for Medical and Insurance Fraud

Because this breach involves a healthcare provider, patients should closely review any medical bills or insurance statements they receive. If you see charges for services you never received, this could indicate that your medical identity was used fraudulently.

In addition, contact your health insurance provider if you notice unfamiliar claims on your account. Insurance fraud resulting from stolen medical information can be complex to resolve. Acting quickly reduces the risk of long-term financial or medical record complications.

Be Alert to Phishing Attempts

Following a healthcare data breach, scammers often send emails or texts pretending to be from the hospital or insurance company. These messages may ask you to click links or provide personal information. Because these tactics can appear convincing, it’s important to verify communications directly with the source before responding.

If you receive a suspicious message referencing Arrowhead Regional Medical Center, do not click on any links. Instead, contact the facility directly using verified contact information. This simple step can prevent further exposure of your personal data.

Consider a Credit Freeze or Fraud Alert

If sensitive identifying information was involved in this breach, placing a credit freeze can prevent criminals from opening new accounts in your name. This is one of the strongest protective measures available to consumers concerned about identity theft.

A fraud alert, meanwhile, requires creditors to take extra steps to verify your identity before issuing credit. Both options are free and can be requested directly through the credit bureaus. Because these breaches often lead to prolonged risk, maintaining these protections for an extended period is advisable.

Consult a Data Breach Attorney

If you believe you were affected by the Arrowhead Regional Medical Center data breach, speaking with a data breach attorney can help clarify your legal options. Many attorneys offer free consultations to evaluate whether you qualify for compensation.

Because healthcare data breaches often involve sensitive protected health information, affected patients may have stronger legal claims than in typical retail breaches. As a result, consulting a knowledgeable attorney early can help you understand your rights and any applicable deadlines for taking action.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

View the full list of tracked data breaches →