Arkansas Oral & Maxillofacial Surgeons Data Breach Investigation
Arkansas Oral & Maxillofacial Surgeons reported an incident involving unauthorized access to files that may have contained patients’ personal and protected health information. The official notice says the potentially involved data varied by person and could include Social Security numbers, medical records, insurance information, and payment information. Strauss Borrelli PLLC is investigating the incident and its impact on affected individuals. If you received a notice or believe your information was involved, fill out the secure contact form on this page to learn whether you may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: Arkansas Oral & Maxillofacial Surgeons (Healthcare)
- Incident Type: Reported hacking/IT incident involving potential unauthorized computer access
- Date of Incident: Not specified in the official notice
- Discovery Date: April 7, 2026
- Official Notice Date: August 4, 2026
- Exposed Information: Names, contact details, Social Security numbers, dates of birth, medical record numbers, diagnosis and treatment information, health insurance information, prescription histories, and payment information
- Affected Population: A state regulatory listing reportedly identifies 64,831 affected individuals; the official substitute notice does not state a total
What Happened?
According to the substitute notice issued by Arkansas Oral & Maxillofacial Surgeons, also referred to as AOMS, the organization learned on April 7, 2026, of potential unauthorized access to its computers and initiated an investigation. The notice reports that AOMS took steps to stop unauthorized access and further secure its systems. On June 2, the investigation reportedly determined that an unauthorized third party had acquired files containing patient information. AOMS then worked to identify the contents of those files and locate accurate contact information for potentially affected people.
The notice is dated August 4, 2026, and says notices were recently mailed to potentially affected individuals for whom AOMS had valid addresses. Separately, the supplied incident data identifies July 31, 2026, as the public-listing date for an unspecified state attorney general filing. Available materials characterize the event as a hacking or IT incident, but they do not identify the access method, the duration of access, or whether every listed data element was obtained for every person.
What Information Was Exposed?
Based on the organization’s investigation, the files may have contained patient names, contact information, Social Security numbers or other government identification numbers, dates of birth, medical record numbers, diagnosis information, treatment records, health insurance information, prescription histories, and payment information. The notice emphasizes that not every category was necessarily involved for every individual.
This combination of identity and healthcare data may create risks beyond ordinary financial fraud. Potential misuse could include medical identity theft, fraudulent patient billing, false insurance claims, prescription-related inquiries, or phishing messages that impersonate a medical provider or insurer. Unexpected requests to confirm insurance, treatment, prescription, or payment details should therefore be verified through a trusted contact method.
What Should You Do Next?
- Place a credit freeze or fraud alert: A credit freeze can restrict access to your credit file, while a fraud alert directs creditors to take additional steps to verify your identity. Contact each nationwide credit bureau directly when requesting a freeze.
- Review medical and insurance records: Examine explanation-of-benefits statements, patient portal activity, prescription histories, and medical bills for care, providers, medications, or claims you do not recognize. Report discrepancies to the provider and insurer promptly.
- Monitor financial accounts and credit reports: Check bank and payment account statements for unfamiliar activity. Obtain your credit reports through the federally authorized AnnualCreditReport.com website and dispute accounts or inquiries that are not yours.
- Be cautious about healthcare-related phishing: Do not provide Social Security, insurance, prescription, or payment information in response to an unexpected call, email, or text. Independently contact the medical provider or insurer using a verified number.
- Preserve relevant records: Keep the incident notice, envelopes, suspicious communications, credit reports, insurance statements, receipts, and records of time spent responding. These materials may help document whether the incident caused losses or other harm.
Your Legal Rights
Individuals affected by a healthcare data incident may have rights under federal or state privacy, consumer-protection, contract, or data-security laws. Depending on the facts and applicable law, those rights may include receiving legally required notice, seeking recovery for documented losses, or requesting other available remedies if security or notification duties were not met.
Eligibility for a claim depends on factors such as where a person lives, the information involved, the person’s relationship with the organization, evidence of misuse or expenses, and applicable filing deadlines. Saving notices and records of financial loss, credit monitoring costs, identity-theft response efforts, or time spent addressing suspicious activity can help support an evaluation. This general information is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC investigates privacy and cybersecurity incidents involving sensitive medical and identity data. The firm can review available notices, assess whether a person may fall within the reported affected group, and explain potential legal options based on applicable law and individual circumstances. A consultation does not guarantee that a claim exists or that any particular result will occur.
If you received a breach notification letter from Arkansas Oral & Maxillofacial Surgeons:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










