Arbor Associates Data Breach Exposes Sensitive PHI & PII

Published
July 6, 2025
Updated
August 15, 2025
Arbor Associates Data Breach Exposes Sensitive PHI & PII
Arbor Associates
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Arbor Associates

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On April 17, 2025, Arbor Associates Inc. discovered unusual activity on its network, prompting a response to secure its systems and launch an investigation with the help of independent cybersecurity experts.

The investigation revealed that between April 15 and April 17, certain files may have been acquired without authorization. By May, Arbor Associates determined that these files contained sensitive information belonging to individuals whose data they process on behalf of healthcare providers.

The breach exposed a range of personally identifiable information (PII) and protected health information (PHI). The types of information potentially accessed include first and last names, contact information, age, biological sex, date of birth, service date, CPT or diagnosis code, medical record number, name of insurance and doctor’s name. Affected individuals include 1,545 Texas residents, 8,995 Washington residents, 551 in Massachusetts and one in Montana.

The incident was reported to the California, Massachusetts, Montana, Vermont, Washington and Texas Attorney Generals' offices beginning on July 3, 2025. Arbor Associates has not specified the total number of affected individuals in any public disclosure, but the breadth of information exposed and the nature of Arbor’s work with healthcare providers suggest the impact could be significant.

The data breach was also disclosed to the U.S. Department of Health and Human Services on July 3, 2025.

Arbor Associates' response

Following the discovery of the breach, Arbor Associates acted quickly to secure its network and engaged cybersecurity experts to investigate the incident. The company has implemented additional security measures to reduce the risk of similar incidents in the future.

Arbor Associates is advising affected individuals to remain vigilant by reviewing account statements and explanation of benefits forms for any errors or unrecognized activity. The company recommends that individuals consider obtaining a free copy of their credit report from each of the three major credit bureaus and to place a fraud alert or a security freeze on their credit files if they detect suspicious activity.

Resources for further protection include contact information for the Federal Trade Commission, state attorneys general and credit bureaus. Arbor Associates has provided a dedicated call center at 833-367-8607, available Monday through Friday from 8 a.m. to 8 p.m. Eastern time, to assist those who may have been affected.

More information about the company and its services can be found on the Arbor Associates website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Arbor Associates
Consumers Notification date
Date of Breach
April 18, 2025
Breach Discovered Date
Total People Affected
17040
Information Types Exposed
  • CPT or diagnosis code
  • Medical Records
  • Name of individual
  • Address
  • Medical Information
  • Date of Birth
  • Health Insurance Information
  • Full Date of Birth
  • Health Insurance Policy or ID Number
  • Age

-

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image