Arrowhead Regional Medical Center Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Arrowhead Regional Medical Center
Active investigation Data breach · Healthcare Notices mailed Sep 28, 2026

Received an September 2026 breach notice from Arrowhead Regional Medical Center?

Dapeer Law, P.A. is investigating a potential class action on behalf of patients of Arrowhead Regional Medical Center, a county-operated hospital in San Bernardino County, California, whose personal information may have been exposed in a data security incident at the hospital's outside counsel, Buchalter.

Submit your claim → See what to do No fee unless we recover for you
Breach window
Determined Aug 28, 2026
Unauthorized data taken from Buchalter systems
Notification delay
About 1 month
Discovered Aug 2026, letters dated Sep 28, 2026
Credit monitoring
Offered
Experian IdentityWorks, enroll by Dec 31, 2026
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Arrowhead Regional Medical Center dated September 2026.
  • Your letter, dated September 28, 2026, offered a complimentary Experian IdentityWorks membership.
  • You are, or were, a patient of Arrowhead Regional Medical Center whose information was held by the hospital's outside counsel, Buchalter.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

According to the notice filed with the California Attorney General, San Bernardino County, on behalf of Arrowhead Regional Medical Center, reports that on August 28, 2026, its outside counsel, Buchalter, determined that a limited amount of data had been taken from its systems without authorization. Buchalter secured its systems and engaged third-party computer forensic specialists, who concluded that the incident was isolated and did not compromise Buchalter's broader network.

On September 4, 2026, the investigation found that the affected data set contained information relating to certain Arrowhead Regional Medical Center patients. After gathering the details needed for notification, letters were dated September 28, 2026. The public version of the notice states that patient names were involved along with additional data elements that are not specified in the public letter. The notice also states there is no evidence the information was viewed by a third party or misused. A complimentary Experian IdentityWorks membership is being offered, with enrollment open through December 31, 2026.

Because the data relates to hospital patients, it may include health or treatment related information held in connection with legal matters. Exposure of patient information may raise concerns under HIPAA and California medical privacy and data breach laws. Dapeer Law is evaluating whether affected patients may have claims, including claims related to how patient data was safeguarded by a third-party vendor.

Hospital patients Vendor breach Law firm data incident California Attorney General filing Health information
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter lists the specific categories of your information involved, which the public version of the notice does not, and it contains your Experian enrollment code. It is also important evidence if you decide to participate in a lawsuit.

2

Enroll in the free Experian IdentityWorks membership

Enroll in the Experian IdentityWorks membership offered in your letter before the December 31, 2026 deadline. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Also review current and past credit or debit card statements, and report any suspicious transactions to your bank right away.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

Aug 28, 2026 Passed
Buchalter determines data was taken without authorization
Sep 4, 2026 Passed
Affected data found to include Arrowhead Regional Medical Center patient information
Sep 28, 2026 Passed
Notice letters dated and filed with the California Attorney General
Dec 31, 2026 Active
Deadline to enroll in Experian IdentityWorks
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, medical identity theft or fraudulent insurance claims, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Arrowhead Regional Medical Center and its vendors, including outside counsel, to implement stronger data security practices for patient information going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Arrowhead Regional Medical Center. What should I do? +

Keep the letter and enroll in the complimentary Experian IdentityWorks membership before December 31, 2026. Review your current and past credit or debit card statements, report any suspicious transactions to your bank immediately, and consider a free case evaluation with a data breach attorney to understand your rights.

Am I eligible to join a class action against Arrowhead Regional Medical Center? +

If you received a breach letter dated September 28, 2026 about Arrowhead Regional Medical Center patient information, you may qualify. Eligibility can depend on your state of residence, the categories of data listed in your letter, and any losses or misuse you have experienced. A free consultation can clarify where you stand.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The public notice lists patient names along with additional data elements that are not specified in the public version of the letter. No Social Security or financial account numbers are specifically mentioned in the public notice. Check your individual letter, which should list the specific categories involved for you.

Did Arrowhead Regional Medical Center offer free credit monitoring? +

Yes. The letter offers a complimentary Experian IdentityWorks membership, with enrollment open through December 31, 2026. Enrolling does not waive your right to pursue a claim.

How many people were affected by the Arrowhead Regional Medical Center breach? +

The notice filed with the California Attorney General does not state how many patients were affected. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The notice was filed with the California Attorney General, which publishes it on its data breach website. You can download it using the official notice link on this page, or contact Dapeer Law and we can help you obtain a copy during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with San Bernardino County on behalf of Arrowhead Regional Medical Center, Experian IdentityWorks, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 28, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Nishiyamato Academy of California Data Breach Lawsuit Investigation

Next
Next

DriveWealth Data Breach Lawsuit Investigation