Academic Urology & Urogynecology of Arizona experienced an external system breach (hacking) that resulted in unauthorized access to its network. The intrusion occurred between May 18-22, 2025, and was detected on May 22, 2025. The company publicly disclosed the breach in August 2025, and confirmed the extent of the compromise on January 30, 2026. Academic Urology & Urogynecology of Arizona began notifying affected individuals on February 12, 2026.
The breach compromised a wide range of sensitive data for approximately 73,281 individuals. This includes personal identifiers such as names, Social Security numbers, dates of birth, addresses, government-issued ID numbers (driver's licenses), passport numbers, tribal identification, and digital signatures. Financial data, including credit/debit card information, financial account numbers, and taxpayer ID numbers, was also exposed. Additionally, the breach involved health insurance information (policy numbers, subscriber ID numbers, group numbers, claim numbers, member numbers, patient identification numbers, and medical benefits/entitlements) and medical records (diagnoses, conditions, lab results, medications, treatment locations, procedure types, provider names, dates of service, and prescription information). The company is offering eligible victims free credit monitoring and identity theft protection.
More details may emerge as investigations continue. Notices to affected individuals may also be delayed.