DataBreachLegalCenter.com
MonitoringCalifornia AG filing · September 28, 2026

San Bernardino County: Arrowhead Regional Medical Center Patient Data Exposed

San Bernardino County reported a data security incident on behalf of its Arrowhead Regional Medical Center, indicating patient personal and health data was compromised. Individuals who received a notification letter should understand the specific data affected and their potential legal options.

Received a San Bernardino County on behalf of Arrowhead Regional Medical Center notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
California
Breach date
August 28, 2026
Reported
September 28, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

San Bernardino County, which operates Arrowhead Regional Medical Center (ARMC), officially reported a data security incident on September 28, 2026. This breach, which occurred on August 28, 2026, involved the exposure of sensitive patient information held by the healthcare provider. The full extent and mechanics of the intrusion are currently under ongoing investigation.

The compromised information includes highly personal details such as Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. This combination of data can pose significant risks to those affected.

Unlike financial data that can be easily replaced, this type of exposed medical and personal identification information carries long-term risks. It could be used for medical identity theft, where an unauthorized person uses your identity to obtain healthcare services, potentially leading to incorrect medical records and impacts on your care. The exposure of Social Security Numbers, combined with other identifiers, also raises the risk of financial fraud and other identity-related crimes.

If you received a data breach notification letter from San Bernardino County regarding Arrowhead Regional Medical Center, it means your private information was confirmed to be compromised. It is advisable to carefully review the notification for details specific to your situation. You should also consider monitoring your credit reports and medical statements for any suspicious activity.

Receiving this official letter confirms that your records were part of the breach. This provides you with a standing to seek further information or explore potential legal avenues. Understanding the specific details of the breach and the types of data exposed is a crucial first step in protecting yourself.

Our firm is actively investigating the San Bernardino County/Arrowhead Regional Medical Center data breach. We offer a free, no-obligation case review for individuals who received a notification letter. This review can help you understand your legal position and potential next steps, without any upfront costs.

Received a San Bernardino County on behalf of Arrowhead Regional Medical Center notification letter? Our legal team tracks every San Bernardino County on behalf of Arrowhead Regional Medical Center data breach filing and offers a free case review. See the full San Bernardino County on behalf of Arrowhead Regional Medical Center case file on DataBreachClassActions

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases