Arbor Associates, Inc., a business associate for healthcare providers, experienced a hacking incident where unauthorized network access occurred between April 15 and April 17, 2025. The company learned of this incident, which may have involved protected health information, and began sending written notices to affected individuals starting July 3, 2025. Notices were also sent to state Attorney General offices in California, Massachusetts, Montana, Vermont, Washington, and Texas, and the incident was reported to the U.S. Department of Health and Human Services on July 3, 2025.
Approximately 11,092 individuals are reported to have been affected, though some sources state as many as 17,040 individuals. The compromised data types include names, Social Security numbers, dates of birth, addresses, government IDs, medical information, and financial information. This also includes PHI and PII such as age, sex, date of birth, service date, CPT/diagnosis code, medical record number, insurance names, and doctor's names. It remains unclear precisely how many individuals were notified by Arbor Associates, Inc.
Details about data breaches can emerge over time, and consumer notifications may be delayed.