Arkansas Oral & Maxillofacial Surgeons discovered potential unauthorized access to its computer systems on April 7, 2026. After an investigation, the practice determined on June 2, 2026, that an unauthorized third party had acquired files containing patient information. The incident was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on August 4, 2026. Reports also linked the incident to a ransomware attack and stated that data was posted on the dark web on April 10, 2026. The information potentially exposed varied by individual and included Social Security numbers, government identification numbers, names, contact information, dates of birth, medical record numbers, diagnosis information, treatment records, health insurance information, prescription history, payment information, and financial account information. The number of affected individuals has not been publicly disclosed in the sources reviewed. Arkansas Oral & Maxillofacial Surgeons began sending mailed notices to potentially affected individuals, but the sources do not provide a specific consumer-notification date. Further incident details may be disclosed as regulatory records and individual notices become available.