DataBreachLawGroup.com
InvestigationMonitoring

San Bernardino County Arrowhead Medical Center Breach Investigation

By Data Breach Law Group | Posted on September 28, 2026 · California

San Bernardino County, on behalf of Arrowhead Regional Medical Center, reported a 2026 data security incident involving highly sensitive patient information. Exposed data includes Full Name, Date of Birth, Social Security Number, and comprehensive medical details. Our firm is investigating potential legal claims on behalf of affected individuals.

Our law firm has launched an investigation into the data breach reported by San Bernardino County on behalf of Arrowhead Regional Medical Center (ARMC). The breach, filed on September 28, 2026, involves the exposure of sensitive patient and personal information maintained by the public teaching hospital in California.

The compromised data categories reported include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The exposure of such a broad range of personal and medical identifiers can lead to severe and lasting risks for affected individuals.

Unlike financial data that can be replaced, core identity and health records are permanent. This exposure creates a heightened risk for medical identity theft, where unauthorized parties might use compromised information to obtain medical services or prescriptions. Additionally, the combination of Social Security Numbers with other personal details significantly increases the danger of financial account takeover, fraudulent loan applications, and tax fraud.

Entities like San Bernardino County and Arrowhead Regional Medical Center are legally obligated under federal laws like HIPAA and HITECH, as well as California state laws, to implement robust security measures to protect sensitive data. A widespread data breach suggests that these mandated safeguards may have been inadequate, potentially constituting a failure of the duty of care owed to patients and staff.

If you have received an official data breach notification letter from San Bernardino County regarding the Arrowhead Regional Medical Center incident, it confirms that your private records were compromised. Receiving this notice establishes your standing to seek legal redress. Even without immediate financial fraud, the increased, imminent risk of future identity theft and the burden of credit and medical record monitoring are recognized as actionable injuries. We invite you to contact us for a free, confidential case review.

Source: California Attorney General breach notification record

If you were affected

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Did you receive a letter from San Bernardino County on behalf of Arrowhead Regional Medical Center?

A case review is free and confidential. Tell us about your letter and we will explain your options.

Got a Notification Letter? Find Out If You Qualify

Free review. No cost, no obligation.

Upload your breach letter (optional)

No attorney-client relationship is created by submitting this form. Attorney Advertising.

Related investigations

This page is attorney advertising and is for general informational purposes only. It is not legal advice, and contacting Data Breach Law Group does not create an attorney-client relationship. Case details are drawn from publicly reported breach notifications and may be updated as more information becomes available. Prior results do not guarantee a similar outcome.

San Bernardino County Data Breach 2026: ARMC Patient Data | DataBreachLawGroup.com