Arizona Breach Tracker
Every Arizona breach and ransomware attack on the public record
Arizona organizations have reported 164 healthcare data breaches to federal regulators, affecting 16,196,141 people, and ransomware crews have named 55 Arizona organizations on their extortion sites. This page pulls both public records into one place, filtered to Arizona, and refreshes every month.
Updated August 3, 2026. Sources: the HHS Office for Civil Rights breach portal and ransomware.live. Free to cite with a link.
164
HIPAA breaches reported by Arizona entities, all years on the federal portal
16.2M
People affected across those breaches
55
Arizona organizations named on ransomware leak sites
10
New HIPAA breaches filed in the last 12 months
The two records on this page answer different questions, which is exactly why it is worth reading them together. The federal breach portal tells you what Arizona healthcare organizations were legally required to admit. The ransomware leak sites tell you what criminal groups are willing to brag about. Neither is complete on its own, and the gap between them is the part most Arizona businesses never see.
The clearest pattern in the Arizona healthcare data is that hacking overtook everything else. 94 of the 164 reported breaches are logged as hacking or IT incidents, and the most common place the data was sitting is a network server. Losing a laptop still happens, but it is no longer the story. The story is someone getting into a server.
On the ransomware side, the crew posting the most Arizona victims is medusa, with 8 listings, and the sector taking the most hits is professional services at 23 listings. These are not hospital systems and household names. They are contractors, law firms, school districts, and family businesses, which is a fair description of most of the Arizona economy.
Arizona HIPAA breaches reported per year
Breaches affecting 500 or more individuals, counted by the date the Arizona entity filed with federal regulators rather than the date of the incident.
* 2026 is a partial year, and recent months undercount because entities have up to 60 days to report.
Arizona organizations named on ransomware leak sites
Counted by the date the extortion post appeared. Coverage of leak sites has broadened over the years, so the earliest year here understates reality more than the recent ones do.
* 2026 is a partial year.
How the Arizona breaches happened
Where the data was sitting
Ransomware groups posting Arizona victims
Arizona sectors named by ransomware crews
Organizations that show up in both records
These Arizona organizations filed a HIPAA breach with federal regulators and were separately named by a ransomware crew. Matching is on organization name, so treat each pairing as strongly indicated rather than officially confirmed.
| Organization | People affected | Filed with OCR | Claimed by |
|---|---|---|---|
| Academic Urology & Urogynecology of Arizona | 73,281 | Feb 13, 2026 | incransom |
| SimonMed Imaging | 1,275,669 | Mar 27, 2025 | medusa |
| OnePoint Patient Care | 1,741,152 | Oct 14, 2024 | incransom |
| Sun Pain Management, LLC | 2,988 | Jan 27, 2024 | medusa |
Most recent Arizona HIPAA breaches
The 15 most recent filings by Arizona entities. The full set of 164 is on the federal portal.
| Entity | Type | People affected | Cause | Filed |
|---|---|---|---|---|
| Southwest Behavioral Health Services.org | Healthcare Provider | 2,316 | Hacking/IT Incident | May 20, 2026 |
| Team Select | Healthcare Provider | 949 | Hacking/IT Incident | Mar 12, 2026 |
| Academic Urology & Urogynecology of Arizona | Healthcare Provider | 73,281 | Hacking/IT Incident | Feb 13, 2026 |
| Glendale Obstetrics & Gynecology PCA | Healthcare Provider | 501 | Hacking/IT Incident | Dec 24, 2025 |
| Better Vision Eyecare, LLC | Healthcare Provider | 501 | Unauthorized Access/Disclosure | Oct 28, 2025 |
| VirMedice, LLC | Business Associate | 1,000 | Hacking/IT Incident | Oct 25, 2025 |
| Coalesce, LLC dba Benefitelect | Business Associate | 501 | Hacking/IT Incident | Oct 15, 2025 |
| Arizona Health Care Cost Containment System- State Medicaid Agency | Health Plan | 3,177 | Unauthorized Access/Disclosure | Oct 3, 2025 |
| Survival Flight, Inc. | Healthcare Provider | 97,217 | Hacking/IT Incident | Sep 15, 2025 |
| Integrated Orthopedics of Arizona | Healthcare Provider | 2,916 | Hacking/IT Incident | Aug 11, 2025 |
| Tri-City Cardiology Consultants, P.C. | Healthcare Provider | 22,753 | Hacking/IT Incident | May 8, 2025 |
| Arizona Arthritis and Rheumatology Associates, P.C. | Healthcare Provider | 5,509 | Hacking/IT Incident | May 2, 2025 |
| Summit Healthcare Medical Associates | Healthcare Provider | 1,861 | Unauthorized Access/Disclosure | Apr 11, 2025 |
| COSE Healthcloud Solutions, LLC | Healthcare Clearing House | 2,606 | Unauthorized Access/Disclosure | Mar 31, 2025 |
| SimonMed Imaging | Healthcare Provider | 1,275,669 | Hacking/IT Incident | Mar 27, 2025 |
Most recent Arizona ransomware listings
Posted by the attacking group on its own leak site. A listing is a criminal claim, not a confirmed incident, and organizations that paid quietly usually never appear at all.
| Organization | Location | Sector | Group | Posted |
|---|---|---|---|---|
| V&P Nurseries | Arizona | Agriculture and Food Production | incransom | Jul 18, 2026 |
| Burris MacOmber | Tucson | Professional Services | thegentlemen | Jun 18, 2026 |
| Avanti Windows & Doors | El Mirage | Manufacturing | aurora | May 12, 2026 |
| Arizona Professional Painting | Phoenix | Professional Services | thegentlemen | May 8, 2026 |
| Avnet | Phoenix | Technology | fulcrumsec | May 1, 2026 |
| Structures Stucco | Phoenix | Manufacturing | thegentlemen | Apr 8, 2026 |
| Abbott Media Productions | Tucson | Professional Services | interlock | Feb 16, 2026 |
| Phoenix Art Museum | Phoenix | Education | rhysida | Feb 12, 2026 |
| Arizona Lighting Sales | Arizona | Retail & E-Commerce | play | Feb 12, 2026 |
| Richey Tax Solutions | Tucson | Financial Services | akira | Feb 4, 2026 |
| Benchmark Electronics Inc | Arizona | Technology | everest | Dec 6, 2025 |
| AZpro Group (azprogroup.com) | Arizona | Professional Services | J | Sep 29, 2025 |
| CCMC | Scottsdale | Professional Services | medusa | Sep 23, 2025 |
| Udall Law Firm | Tucson | Professional Services | akira | Sep 10, 2025 |
| Republic Services | Phoenix | Professional Services | shinyhunters | Jun 30, 2025 |
Methodology
Everything here is rebuilt from source each month by a script, so the numbers on this page are reproducible rather than hand-maintained. Both inputs are public records. No client data of ours is involved, and no system belonging to any organization named on this page was accessed to build it.
Healthcare breaches
Pulled from the HHS Office for Civil Rights breach portal, which publishes every breach of unsecured protected health information affecting 500 or more individuals. The portal separates cases currently under investigation, roughly the last two years, from an archive of resolved cases, and this tracker reads both, then filters to rows where the reporting entity's state is Arizona and removes duplicates across the two sets. As of this update that is 164 Arizona rows out of 7,835 nationally.
Two caveats matter for interpretation. The state on a record is the reporting entity's state, so an Arizona business associate serving clients elsewhere still counts as Arizona, and the people affected may not live here. And the count of people affected is dominated by a handful of very large incidents, so a total across all years says more about those few events than about typical risk.
Ransomware listings
Pulled from the ransomware.live API, which archives posts from ransomware extortion sites. The source records country but not state, so Arizona has to be read out of the description text stored with each listing. A listing is published on this page only when that text makes a location claim: a city paired with the state, an Arizona postal address, a description of the organization as Arizona-based, or an Arizona location line in the profile.
Listings where Arizona appears only in a list of several states are held back rather than published, because that pattern reliably indicates a national company with some Arizona presence rather than an Arizona organization. Held entries go to a review file and are added only after a person confirms the location. That filter is deliberately strict, which means this page undercounts. Treat 55 as a floor.
Update cadence
Monthly. Federal breach reporting lags real incidents by design, because covered entities have up to 60 days from discovery to notify and the portal is refreshed in batches, so the most recent month on this page is always incomplete and will grow after publication.
Using this data
Journalists, researchers, and other Arizona firms are welcome to cite and republish these figures with a link back to this page so readers can check the method. If you need a cut we do not publish, such as a single sector, a city, or a specific date range, ask and we will pull it.
Questions about this tracker
Where does this data come from?
Two public sources. Healthcare breaches come from the U.S. Department of Health and Human Services Office for Civil Rights breach portal, which lists every HIPAA breach affecting 500 or more individuals and includes the state of the reporting entity. Ransomware entries come from ransomware.live, which archives the extortion leak sites where criminal groups publish their victims. Both are public. Neither is a Desert Lakes Solutions dataset, and nothing here comes from client systems.
Does a listing mean the organization did something wrong?
No. A HIPAA breach report is a legal notification requirement, not a finding of fault, and many entries involve a vendor or a mailing error rather than a security failure. A ransomware leak-site listing is a criminal group's own claim, which is sometimes exaggerated, occasionally recycled from an older incident, and never independently verified by the people posting it. Treat both as starting points for a question, not as a verdict.
Why do the ransomware numbers look low compared to the healthcare numbers?
Because they measure different things over different spans. The federal portal has collected HIPAA breach reports since 2009 and reporting is mandatory, so the record is deep and fairly complete. Leak-site tracking is younger and entirely voluntary on the attacker's side. Victims who pay quickly are often never posted at all, so the ransomware count is a floor, not a total.
How is an Arizona ransomware victim identified when the source has no state field?
By reading the victim description that the tracker records for each listing. An entry is published here only when that text states an Arizona location, such as a city and state pairing, an Arizona postal address, or a description of the organization as Arizona-based. Listings that merely mention Arizona among several states, which is typical of national companies, are held back for manual review rather than published. The methodology section below spells this out in full.
How often is it updated?
Monthly. The federal portal itself lags real events by design, because covered entities have up to 60 days to notify after discovering a breach and the portal is refreshed in batches, so checking more often than monthly surfaces very little that is new.
Can I use this data in an article or report?
Yes. The figures are drawn from public federal and open-source records, and we would ask that you cite this page and link back so readers can see the methodology and the source links for themselves. If you need a cut we do not publish here, such as a specific sector, city, or date range, get in touch and we will pull it.
Want to know where your organization would land on a list like this?
The pattern in the Arizona data is consistent: a server reached from outside, or an email account opened by someone who should not have had it. Tell us what you are running and we will tell you plainly whether you have a real gap or a manageable one.
Call (855) 737-9500 / (480) 573-3349
Email [email protected]
15-minute response on critical issues, 24/7. Onboarding in two to three weeks.