Skip to main content
Jump to a category page

Patient information from Arrowhead Regional Medical Center was taken in a data breach at Buchalter LLP, a law firm that does legal work for the hospital. The breach was found on August 28, 2026, and patients were notified one month later.

Arrowhead Regional Medical Center (ARMC) is a public hospital run by San Bernardino County in Colton, California. Buchalter LLP is a law firm that provides legal services to ARMC. On August 28, 2026, Buchalter learned that an unauthorized person had taken, or “acquired,” a limited set of Buchalter data.

According to the notice letter, Buchalter said the incident was isolated. The firm said it found no evidence that the actor got into Buchalter’s network or systems. Buchalter hired data mining experts to review the affected files. On September 4, 2026, that review found ARMC patient information, and Buchalter told ARMC. San Bernardino County reported the breach to the California Attorney General on September 28, 2026, and sent letters dated the same day.

The notice states that there is no evidence the information has been viewed by any third party or misused. Buchalter also reported the incident to law enforcement.

Why Patient Data at a Hospital’s Law Firm Matters

Most patients never think about the outside companies their hospital works with. Hospitals share patient records with lawyers, billing firms, and other vendors to handle claims, disputes, and legal matters. When one of those vendors is breached, patient data can be exposed even though the hospital’s own systems were not attacked.

That is what happened here. The breach took place at Buchalter, not at ARMC. The patients affected had no direct relationship with the law firm. They likely did not know the firm had their information until the letter arrived.

The Timeline From Discovery to Notice

  • August 28, 2026: Buchalter learns that some of its data was acquired without permission.
  • September 4, 2026: Buchalter’s review finds ARMC patient information and Buchalter notifies ARMC.
  • September 21, 2026: Buchalter secures the information needed to mail notices.
  • September 28, 2026: Letters are dated and the breach is reported to the California Attorney General.

In total, about one month passed between discovery and notice.

How Many People Were Affected by the Buchalter Breach?

Neither Buchalter nor San Bernardino County has disclosed how many patients were affected. The California Attorney General listing does not include a count. The notice also does not say whether clients of Buchalter other than ARMC had data in the same files.

What Information Was Exposed?

The letter describes the affected data as ARMC patient information. Based on the sample notice posted with the California Attorney General, the compromised information includes:

  • Patient name
  • Other data elements listed in each individual letter

The posted sample leaves the specific list of other data elements as a blank template field. Each patient’s letter should state which information was involved for that person. Patients should read that section of their letter carefully.

What Is Being Offered to Affected ARMC Patients?

The notice offers a complimentary membership in Experian IdentityWorks, a credit monitoring and identity protection service. The posted sample leaves the length of the membership blank, so each letter should state it.

  • Enrollment deadline: December 31, 2026, at 11:59 p.m. UTC
  • Enroll online at experianidworks.com/1Bcredit using the activation code in the letter
  • Questions: call 866-566-1941, Monday through Friday, 6 a.m. to 6 p.m. Pacific Time

Your Information Is at Risk

Health-related information is valuable to criminals. It can be used to bill insurance for care that never happened or to get medical services in someone else’s name. Unlike a credit card, a person’s medical history cannot be canceled and reissued.

Affected individuals should:

  • Enroll in the Experian IdentityWorks offer before December 31, 2026.
  • Review Explanation of Benefits statements from insurers for visits or services that did not happen.
  • Request a copy of medical records if something looks wrong.
  • Place a free credit freeze with Equifax, Experian, and TransUnion.
  • Be wary of calls or emails that mention ARMC or Buchalter and ask for personal details.

Do You Have Legal Options?

Hospitals and the vendors they share patient data with have a legal obligation to protect that information. That includes law firms that receive patient records for legal work. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney.

Emery | Reddy is investigating the Buchalter LLP data breach and its impact on ARMC patients. There is No Fee Unless We Recover.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

How many people were affected by the Buchalter data breach?

The total has not been disclosed. The California Attorney General listing and the sample notice do not give a number.

What information was exposed?

The notice says ARMC patient information was involved, including patient names. The public sample does not list the other data elements. Your own letter should state which information was involved for you.

Were ARMC’s own systems breached?

The notice describes an incident at Buchalter LLP, a law firm that does legal work for ARMC. It does not describe any breach of ARMC’s own systems. Buchalter told ARMC on September 4, 2026, that ARMC patient information was in the affected data.

Why did it take a month to notify patients?

According to the notice, Buchalter first had experts review the affected files to find whose information was inside. It found ARMC patient data on September 4, 2026, and secured the information needed to send letters on September 21, 2026. Letters were dated September 28, 2026.

What should I do if I received a notification letter?

  • Keep the letter and the envelope.
  • Enroll in Experian IdentityWorks before December 31, 2026.
  • Check insurance statements for care you did not receive.
  • Freeze your credit with all three credit bureaus.

What harm can come from a medical data breach?

Medical and health data can be used for medical identity theft. That can mean fake insurance claims, false entries in your medical records, or bills for care you never received. These problems can take a long time to find and fix, so checking insurance statements over time is important.

How can I protect myself from scams that mention the breach?

Criminals often send fake follow-up messages after a breach. They may use the hospital’s or law firm’s name to seem real. Do not click links or share information in a message you did not expect. Call ARMC or the Experian number printed in your letter instead.

Do I have a legal claim?

Hospitals and the vendors they trust with patient records have a duty to protect that data and to tell you when it is exposed. If that duty was not met, you may have rights. Because ARMC is a county hospital, claims involving a public entity can have short filing deadlines, so it can help to speak with a lawyer early. If you received a notice letter from Buchalter LLP or ARMC, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now