DataBreachCaseFile.com
MonitoringCalifornia AG filing · September 28, 2026

San Bernardino County: Arrowhead Regional Medical Center Data Compromise

San Bernardino County, on behalf of Arrowhead Regional Medical Center, filed a report on September 28, 2026, concerning a data security incident. This breach, discovered on August 28, 2026, exposed various types of sensitive personal and health information. Individuals potentially affected should carefully review official notifications for details on the exposed data.

State
California
Breach date
August 28, 2026
Reported
September 28, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

San Bernardino County, operating Arrowhead Regional Medical Center (ARMC), reported a data security incident to regulators on September 28, 2026. The breach was identified on August 28, 2026, and its specific type remains unspecified as the investigation is currently monitoring the situation. ARMC is a significant public teaching hospital in California, handling extensive patient data.

The reported exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. This combination of identifying and sensitive health information presents a significant risk to affected individuals. The exposure of such comprehensive records can lead to various forms of identity-related misuse.

As a large county-run medical facility, ARMC manages a vast repository of sensitive information crucial for patient care and administrative functions. The occurrence of a data breach at such an institution highlights the constant security challenges faced by healthcare providers and the potential impact on individuals whose private records are entrusted to them. Details on the full mechanics of the incident are still under evaluation.

Individuals who receive official notification regarding this incident should take proactive steps to protect themselves. It is advisable to carefully review any communication from San Bernardino County or Arrowhead Regional Medical Center. Consider placing a fraud alert or security freeze on your credit reports with the major credit bureaus to help prevent unauthorized accounts from being opened in your name. Additionally, regularly monitor your financial statements, health insurance explanations of benefits (EOBs), and medical records for any unusual activity or discrepancies.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases