Arkansas Urology discovered unauthorized access to employee email accounts in July 2026, with hackers potentially viewing messages through mid-August 2026. Exposed data for some patients included Social Security numbers, driver’s license numbers, medical information and health insurance details. Notification letters went out starting October 2026. Affected patients should enroll in the free TransUnion identity monitoring offered and watch financial and medical statements closely for signs of fraud.
| Company | Arkansas Urology |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Social Security Numbers, Driver’s License or State ID Numbers, Medical Information, Diagnosis and Treatment Details, Health Insurance Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Email Account Compromise |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Arkansas Urology Data Breach?
Arkansas Urology, a urology practice serving patients in and around Little Rock, has disclosed a data security incident tied to its employee email systems. The practice says it found evidence of unauthorized access in July 2026. As a result, certain employee email accounts were accessed by someone outside the organization without permission.
According to the practice’s own account, the unauthorized access began around July 8, 2026, and may have continued through August 13, 2026. During this window, an outside party may have viewed emails stored in the compromised accounts. Because staff email accounts often contain forwarded patient records and insurance paperwork, this created exposure for sensitive personal data. Arkansas Urology says it responded by activating its incident response plan, taking affected systems offline and resetting passwords.
After containing the intrusion, the practice brought in a cybersecurity firm to investigate further. That review required examining the contents of the affected mailboxes line by line. On September 1, 2026, Arkansas Urology determined that certain messages contained Social Security numbers and other protected health information. This document-by-document review is a common reason breach notifications arrive months after the original intrusion was found.
Who was affected?
The people affected by this incident are patients of Arkansas Urology whose personal or medical information passed through the compromised employee email accounts. Because urology practices handle sensitive diagnostic and treatment records, the exposed data could include detailed health histories alongside identification numbers.
Arkansas Urology has not publicly disclosed the total number of patients affected nationwide. Its regulatory notice to New Hampshire’s Attorney General states that one New Hampshire resident received written notice, but that figure covers only that state. In multi-state breaches like this one, companies typically file separate notices with each state regulator, so no single filing shows the full scope. The overall number of affected individuals has not been made public.
What Information Was Potentially Exposed?
Arkansas Urology’s notification describes several categories of personal and medical information that may have appeared in the compromised email accounts. Not every affected person had the same data exposed, since the specific items vary by individual.
- Social Security numbers
- Driver’s license or state identification card numbers
- Medical information, including diagnosis, diagnosis codes, and mental or physical condition details
- Provider name and treatment location
- Health insurance information
This combination of data is particularly sensitive because it merges financial identifiers with health details. When Social Security numbers and driver’s license numbers are exposed together, criminals can use them to open new credit accounts, file fraudulent tax returns, or impersonate victims with government agencies. This type of harm can surface months or even years after a breach occurs.
Medical and insurance information carries its own distinct risks. Unlike a password, a diagnosis or insurance ID cannot simply be changed after exposure. As a result, this data can fuel medical identity theft, where someone uses stolen insurance details to obtain treatment or prescriptions under another person’s name. It can also be used to craft convincing phishing messages that reference real diagnoses or providers, making scams harder to detect.
What is the company doing?
Arkansas Urology says it moved quickly once it discovered the intrusion. The practice took the affected systems offline, reset account passwords and brought in outside cybersecurity specialists to investigate the scope of the access. This response helped the practice identify which mailboxes were involved and what information they contained.
Following the investigation, Arkansas Urology began sending written notification letters to affected patients starting October 1, 2026. The practice is also offering twenty-four months of complimentary identity monitoring through TransUnion to those impacted. In addition, Arkansas Urology filed formal notification of the incident with the New Hampshire Attorney General, as required under that state’s breach notification law.
Arkansas Urology states it is not aware of any confirmed misuse of patient information connected to this incident so far. However, the practice says it continues working with its IT professionals to strengthen network defenses. It also says it will keep reviewing its security policies and procedures going forward.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone notified of this breach should check their credit reports regularly for unfamiliar accounts or inquiries. You can get free reports from all three major bureaus at annualcreditreport.com. Reviewing these reports often is one of the simplest ways to catch identity theft early.
Because Social Security numbers were involved, this risk extends well beyond the next few months. Identity thieves sometimes wait before using stolen data, so ongoing vigilance matters more than a one-time check. Consider setting a recurring reminder to pull your reports every few months.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers and driver’s license numbers were exposed, placing a fraud alert or credit freeze is a strong protective step. A freeze restricts access to your credit file, making it harder for criminals to open new accounts in your name. You can request one through Equifax, Experian and TransUnion.
A fraud alert is a lighter-touch option that requires lenders to verify your identity before extending credit. Either option is free to set up. For individuals especially concerned about long-term exposure, a credit freeze generally offers stronger protection than an alert alone.
Watch for Signs of Medical Identity Theft
Because medical information and health insurance details were exposed, patients should review their explanation of benefits statements carefully. Look for services, prescriptions or appointments that you do not recognize. If anything looks unfamiliar, contact your insurer right away.
Medical identity theft can also affect your actual medical records if false information gets mixed in. This could create confusion during future treatment. Therefore, catching discrepancies early and reporting them promptly is important for both your finances and your health care accuracy.
Enroll in the Offered Identity Monitoring Service
Arkansas Urology is offering twenty-four months of complimentary identity monitoring through TransUnion to affected individuals. If you received a notification letter, it should include instructions for enrolling in this service. Taking advantage of this free monitoring is a practical first step.
This service can alert you to suspicious activity tied to your personal information faster than manually checking accounts yourself. Even so, it should supplement, not replace, your own regular reviews of financial and medical statements. Combining both approaches gives you broader protection.
Stay Alert to Phishing and Scam Attempts
After a healthcare data breach, scammers sometimes send fake messages pretending to be the breached organization or an insurer. Be cautious with unexpected calls, texts or emails that reference Arkansas Urology or your medical history. Never click links or share information from messages you did not expect.
Instead, rely only on the contact details printed in your official notification letter. If you are ever unsure whether a message is legitimate, call the practice directly using a number you look up independently. This extra step can prevent you from becoming a victim of a follow-up scam.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
