Arkansas Urology Data Breach Exposes Social Security Numbers and Medical Records

Published: 5 October 2026
Healthcare data breach illustration
Breach Discovery: July 2026Breach Notification: October 2026

Arkansas Urology discovered in July 2026 that an unauthorized person accessed employee email accounts containing patients’ Social Security numbers, driver’s license numbers, medical information and health insurance details. The practice began notifying affected patients in October 2026 and is offering free TransUnion identity monitoring for two years. Affected individuals should enroll in monitoring, check credit reports, and watch for phishing attempts referencing the breach.

CompanyArkansas Urology
IndustryHealthcare
Data Types ExposedSocial Security Numbers, Driver’s License or State ID Numbers, Medical Information, Health Insurance Information
People AffectedNot Publicly Disclosed
Attack MethodEmail Account Compromise
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Arkansas Urology Data Breach?

Arkansas Urology, a Little Rock-based urology practice, has told patients that someone broke into employee email accounts without permission. The practice discovered the intrusion in July 2026. According to its notice, unauthorized access to certain mailboxes occurred on or around July 8, 2026.

Investigators later determined the unauthorized individual could have accessed those accounts through August 13, 2026. As a result, the exposure window spans more than a month. During that stretch, whoever broke in may have viewed emails containing sensitive patient details.

Once the practice spotted the suspicious activity, it says it moved quickly. It reports taking certain systems offline and resetting passwords to contain the threat. The practice then brought in a cybersecurity firm to examine what happened and determine which accounts were touched.

That forensic work took time. On September 1, 2026, Arkansas Urology confirmed that some of the affected messages held Social Security numbers and other protected health information. Because mailboxes often contain years of accumulated attachments, reviewing every message individually is a slow process. This is a common reason breach notification timelines stretch for months.

Who Was Affected?

The people affected by this incident are patients of Arkansas Urology who had personal or medical information stored in employee email accounts. Since the practice serves patients throughout central Arkansas, the exposure likely touches individuals across that region.

The total number of affected people has not been publicly disclosed. The only figure included in regulatory paperwork covers New Hampshire, where the practice notified a single resident. That number does not reflect the full scope of the breach nationwide.

Because this was a healthcare provider, the exposed population may include people of varying ages, including minors who received care at the practice. Patients should not assume they’re unaffected simply because they live outside Arkansas. Email-based breaches often cross state lines since providers may treat patients who have since moved.

What Information Was Potentially Exposed?

Arkansas Urology’s notice describes several categories of personal and medical information found in the compromised email accounts. Because the content of each mailbox varied, not every patient will have had the same information exposed.

  • Social Security numbers
  • Driver’s license or state identification card numbers
  • Medical information, including diagnosis, diagnosis code, mental or physical condition, and provider name and location
  • Health insurance information

This combination of data creates serious risk. Social Security numbers and driver’s license numbers are the building blocks of identity theft. Criminals can use them to open new credit accounts, file fraudulent tax returns, or take out loans in a victim’s name.

Medical and insurance information carries its own distinct danger. Unlike a password, a diagnosis or insurance ID number cannot simply be changed. As a result, this type of data can fuel medical identity theft, where someone uses a victim’s insurance details to obtain treatment or prescriptions, potentially corrupting the victim’s own medical records in the process.

What is the Company Doing?

After discovering the intrusion, Arkansas Urology says it acted immediately to contain it. The practice reports taking affected systems offline and resetting account passwords before bringing in outside cybersecurity experts to investigate further.

Following the investigation, the practice began notifying affected patients in writing on October 1, 2026. It is also offering complimentary identity monitoring through TransUnion for twenty-four months to those impacted. The practice has stated it is not aware of any actual misuse of patient information at this time.

Arkansas Urology also filed formal notification with the New Hampshire Attorney General. In addition, the practice says it continues working with IT professionals to strengthen network security and update its internal policies going forward.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone notified of this breach should check their credit reports regularly. You can get free reports from all three major bureaus at annualcreditreport.com. Reviewing these reports helps you catch new accounts or inquiries you did not authorize.

Because Social Security numbers were involved, this step matters even if you see no immediate signs of trouble. Identity thieves sometimes wait months before using stolen information. Checking consistently, rather than just once, gives you a better chance of catching fraud early.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers and driver’s license numbers were exposed, placing a fraud alert or credit freeze is a smart precaution. A freeze restricts access to your credit file, making it much harder for criminals to open new accounts in your name.

You can request a freeze directly with Equifax, Experian and TransUnion at no cost. While a freeze adds an extra step when you apply for credit yourself, it offers strong protection against unauthorized account openings during a period of heightened risk.

Protect Against Medical Identity Theft

Because medical information and health insurance details were exposed, patients should review their explanation of benefits statements closely. Look for services, prescriptions or appointments you don’t recognize.

If you spot anything unfamiliar, contact your insurer right away. Medical identity theft can be harder to untangle than financial fraud because it may affect your actual treatment records. Catching discrepancies early helps limit the damage and keeps your medical history accurate.

Enroll in Identity Monitoring and Stay Alert for Scams

Arkansas Urology is offering complimentary identity monitoring through TransUnion for twenty-four months. If you received a notice, consider enrolling using the instructions printed in your letter.

In addition, be cautious of unexpected calls, texts or emails referencing this breach. Scammers often use publicized incidents to impersonate real organizations. Only use contact information printed directly in your official notification letter, and report any suspected identity theft to the Federal Trade Commission at identitytheft.gov.

Watch for Phishing Attempts

Because this breach originated through compromised email accounts, affected individuals should be especially alert to phishing attempts that may follow. Fraudsters sometimes craft messages that look like they come from a healthcare provider or insurer.

Never click links or provide personal information in response to an unsolicited message. If you’re ever unsure whether a communication is legitimate, contact the organization directly using a phone number or website you already trust, not one provided in the suspicious message itself.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →