DataBreachLegalTeam.com
MonitoringCalifornia AG filing · September 28, 2026

San Bernardino County / ARMC Data Breach: Patient Data Compromised

San Bernardino County, on behalf of Arrowhead Regional Medical Center (ARMC), reported a data breach in September 2026, exposing sensitive patient information. This incident puts individuals at risk of medical identity theft and financial fraud, underscoring the critical need for victims to understand their legal rights and potential recourse.

Received a San Bernardino County on behalf of Arrowhead Regional Medical Center notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
California
Breach date
August 28, 2026
Reported
September 28, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

San Bernardino County, acting for Arrowhead Regional Medical Center (ARMC), officially reported a data security incident in September 2026. This breach involved the compromise of highly sensitive patient information, specifically exposing Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The incident, which occurred on August 28, 2026, is currently under investigation, meaning the full scope and precise mechanisms of the compromise are still being evaluated.

When information of this nature is exposed, especially the combination of Social Security Numbers with detailed medical and identity data, the risks are substantial and long-lasting. Unlike a credit card that can be replaced, core identity and medical information is permanent. Victims face an increased risk of medical identity theft, where someone could use their name to obtain prescriptions or services, leading to corrupted medical records and potential health dangers. Furthermore, the exposure of Social Security Numbers makes individuals highly vulnerable to severe financial fraud, including account takeovers and fraudulent loan applications.

As a major public healthcare provider in California, San Bernardino County and ARMC are legally obligated to protect patient data under stringent federal and state laws, including HIPAA and California's privacy regulations. The occurrence of a data breach suggests that the required robust administrative, physical, and technical safeguards may have been insufficient. This potential failure in securing sensitive information could indicate a breach of the duty of care owed to patients.

If you have received a data breach notification letter from San Bernardino County on behalf of Arrowhead Regional Medical Center, it means your private information was impacted. This notification confirms your standing to seek legal recourse. Our team is actively investigating this data breach, working to hold responsible parties accountable. We offer free case reviews and represent victims on a contingency fee basis, meaning there are no upfront costs, and we only get paid if we secure compensation for you.

Received the San Bernardino County on behalf of Arrowhead Regional Medical Center notification letter? The San Bernardino County on behalf of Arrowhead Regional Medical Center case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases