Skip to content

Arizona Breach Tracker

Every Arizona breach and ransomware attack on the public record

Arizona organizations have reported 164 healthcare data breaches to federal regulators, affecting 16,196,141 people, and ransomware crews have named 55 Arizona organizations on their extortion sites. This page pulls both public records into one place, filtered to Arizona, and refreshes every month.

Updated August 3, 2026. Sources: the HHS Office for Civil Rights breach portal and ransomware.live. Free to cite with a link.

164

HIPAA breaches reported by Arizona entities, all years on the federal portal

16.2M

People affected across those breaches

55

Arizona organizations named on ransomware leak sites

10

New HIPAA breaches filed in the last 12 months

The two records on this page answer different questions, which is exactly why it is worth reading them together. The federal breach portal tells you what Arizona healthcare organizations were legally required to admit. The ransomware leak sites tell you what criminal groups are willing to brag about. Neither is complete on its own, and the gap between them is the part most Arizona businesses never see.

The clearest pattern in the Arizona healthcare data is that hacking overtook everything else. 94 of the 164 reported breaches are logged as hacking or IT incidents, and the most common place the data was sitting is a network server. Losing a laptop still happens, but it is no longer the story. The story is someone getting into a server.

On the ransomware side, the crew posting the most Arizona victims is medusa, with 8 listings, and the sector taking the most hits is professional services at 23 listings. These are not hospital systems and household names. They are contractors, law firms, school districts, and family businesses, which is a fair description of most of the Arizona economy.

Arizona HIPAA breaches reported per year

Breaches affecting 500 or more individuals, counted by the date the Arizona entity filed with federal regulators rather than the date of the incident.

0 9 17 4 2015 9 2016 8 2017 8 2018 12 2019 12 2020 15 2021 16 2022 17 2023 16 2024 17 2025 3 2026*

* 2026 is a partial year, and recent months undercount because entities have up to 60 days to report.

Arizona organizations named on ransomware leak sites

Counted by the date the extortion post appeared. Coverage of leak sites has broadened over the years, so the earliest year here understates reality more than the recent ones do.

0 11 22 5 2023 22 2024 18 2025 10 2026*

* 2026 is a partial year.

How the Arizona breaches happened

Hacking/IT Incident 94 Unauthorized Access/Disclosure 33 Theft 25 Loss 6 Improper Disposal 3 Other 3

Where the data was sitting

Network Server 71 Email 43 Paper/Films 24 Other 12 Laptop 12 Other Portable Electronic Device 10 Electronic Medical Record 7 Desktop Computer 7

Ransomware groups posting Arizona victims

medusa 8 blackbasta 5 incransom 4 play 4 thegentlemen 3 interlock 3 akira 3 cactus 3 blacklock 2 safepay 2

Arizona sectors named by ransomware crews

Professional Services 23 Education 7 Manufacturing 6 Technology 4 Healthcare 4 Retail & E-Commerce 3 Hospitality 3 Financial Services 2 Agriculture and Food Production 1 Government & Defense 1

Organizations that show up in both records

These Arizona organizations filed a HIPAA breach with federal regulators and were separately named by a ransomware crew. Matching is on organization name, so treat each pairing as strongly indicated rather than officially confirmed.

Organization People affected Filed with OCR Claimed by
Academic Urology & Urogynecology of Arizona 73,281 Feb 13, 2026 incransom
SimonMed Imaging 1,275,669 Mar 27, 2025 medusa
OnePoint Patient Care 1,741,152 Oct 14, 2024 incransom
Sun Pain Management, LLC 2,988 Jan 27, 2024 medusa

Most recent Arizona HIPAA breaches

The 15 most recent filings by Arizona entities. The full set of 164 is on the federal portal.

Entity Type People affected Cause Filed
Southwest Behavioral Health Services.org Healthcare Provider 2,316 Hacking/IT Incident May 20, 2026
Team Select Healthcare Provider 949 Hacking/IT Incident Mar 12, 2026
Academic Urology & Urogynecology of Arizona Healthcare Provider 73,281 Hacking/IT Incident Feb 13, 2026
Glendale Obstetrics & Gynecology PCA Healthcare Provider 501 Hacking/IT Incident Dec 24, 2025
Better Vision Eyecare, LLC Healthcare Provider 501 Unauthorized Access/Disclosure Oct 28, 2025
VirMedice, LLC Business Associate 1,000 Hacking/IT Incident Oct 25, 2025
Coalesce, LLC dba Benefitelect Business Associate 501 Hacking/IT Incident Oct 15, 2025
Arizona Health Care Cost Containment System- State Medicaid Agency Health Plan 3,177 Unauthorized Access/Disclosure Oct 3, 2025
Survival Flight, Inc. Healthcare Provider 97,217 Hacking/IT Incident Sep 15, 2025
Integrated Orthopedics of Arizona Healthcare Provider 2,916 Hacking/IT Incident Aug 11, 2025
Tri-City Cardiology Consultants, P.C. Healthcare Provider 22,753 Hacking/IT Incident May 8, 2025
Arizona Arthritis and Rheumatology Associates, P.C. Healthcare Provider 5,509 Hacking/IT Incident May 2, 2025
Summit Healthcare Medical Associates Healthcare Provider 1,861 Unauthorized Access/Disclosure Apr 11, 2025
COSE Healthcloud Solutions, LLC Healthcare Clearing House 2,606 Unauthorized Access/Disclosure Mar 31, 2025
SimonMed Imaging Healthcare Provider 1,275,669 Hacking/IT Incident Mar 27, 2025

Most recent Arizona ransomware listings

Posted by the attacking group on its own leak site. A listing is a criminal claim, not a confirmed incident, and organizations that paid quietly usually never appear at all.

Organization Location Sector Group Posted
V&P Nurseries Arizona Agriculture and Food Production incransom Jul 18, 2026
Burris MacOmber Tucson Professional Services thegentlemen Jun 18, 2026
Avanti Windows & Doors El Mirage Manufacturing aurora May 12, 2026
Arizona Professional Painting Phoenix Professional Services thegentlemen May 8, 2026
Avnet Phoenix Technology fulcrumsec May 1, 2026
Structures Stucco Phoenix Manufacturing thegentlemen Apr 8, 2026
Abbott Media Productions Tucson Professional Services interlock Feb 16, 2026
Phoenix Art Museum Phoenix Education rhysida Feb 12, 2026
Arizona Lighting Sales Arizona Retail & E-Commerce play Feb 12, 2026
Richey Tax Solutions Tucson Financial Services akira Feb 4, 2026
Benchmark Electronics Inc Arizona Technology everest Dec 6, 2025
AZpro Group (azprogroup.com) Arizona Professional Services J Sep 29, 2025
CCMC Scottsdale Professional Services medusa Sep 23, 2025
Udall Law Firm Tucson Professional Services akira Sep 10, 2025
Republic Services Phoenix Professional Services shinyhunters Jun 30, 2025

Methodology

Everything here is rebuilt from source each month by a script, so the numbers on this page are reproducible rather than hand-maintained. Both inputs are public records. No client data of ours is involved, and no system belonging to any organization named on this page was accessed to build it.

Healthcare breaches

Pulled from the HHS Office for Civil Rights breach portal, which publishes every breach of unsecured protected health information affecting 500 or more individuals. The portal separates cases currently under investigation, roughly the last two years, from an archive of resolved cases, and this tracker reads both, then filters to rows where the reporting entity's state is Arizona and removes duplicates across the two sets. As of this update that is 164 Arizona rows out of 7,835 nationally.

Two caveats matter for interpretation. The state on a record is the reporting entity's state, so an Arizona business associate serving clients elsewhere still counts as Arizona, and the people affected may not live here. And the count of people affected is dominated by a handful of very large incidents, so a total across all years says more about those few events than about typical risk.

Ransomware listings

Pulled from the ransomware.live API, which archives posts from ransomware extortion sites. The source records country but not state, so Arizona has to be read out of the description text stored with each listing. A listing is published on this page only when that text makes a location claim: a city paired with the state, an Arizona postal address, a description of the organization as Arizona-based, or an Arizona location line in the profile.

Listings where Arizona appears only in a list of several states are held back rather than published, because that pattern reliably indicates a national company with some Arizona presence rather than an Arizona organization. Held entries go to a review file and are added only after a person confirms the location. That filter is deliberately strict, which means this page undercounts. Treat 55 as a floor.

Update cadence

Monthly. Federal breach reporting lags real incidents by design, because covered entities have up to 60 days from discovery to notify and the portal is refreshed in batches, so the most recent month on this page is always incomplete and will grow after publication.

Using this data

Journalists, researchers, and other Arizona firms are welcome to cite and republish these figures with a link back to this page so readers can check the method. If you need a cut we do not publish, such as a single sector, a city, or a specific date range, ask and we will pull it.

Questions about this tracker

Where does this data come from?

Two public sources. Healthcare breaches come from the U.S. Department of Health and Human Services Office for Civil Rights breach portal, which lists every HIPAA breach affecting 500 or more individuals and includes the state of the reporting entity. Ransomware entries come from ransomware.live, which archives the extortion leak sites where criminal groups publish their victims. Both are public. Neither is a Desert Lakes Solutions dataset, and nothing here comes from client systems.

Does a listing mean the organization did something wrong?

No. A HIPAA breach report is a legal notification requirement, not a finding of fault, and many entries involve a vendor or a mailing error rather than a security failure. A ransomware leak-site listing is a criminal group's own claim, which is sometimes exaggerated, occasionally recycled from an older incident, and never independently verified by the people posting it. Treat both as starting points for a question, not as a verdict.

Why do the ransomware numbers look low compared to the healthcare numbers?

Because they measure different things over different spans. The federal portal has collected HIPAA breach reports since 2009 and reporting is mandatory, so the record is deep and fairly complete. Leak-site tracking is younger and entirely voluntary on the attacker's side. Victims who pay quickly are often never posted at all, so the ransomware count is a floor, not a total.

How is an Arizona ransomware victim identified when the source has no state field?

By reading the victim description that the tracker records for each listing. An entry is published here only when that text states an Arizona location, such as a city and state pairing, an Arizona postal address, or a description of the organization as Arizona-based. Listings that merely mention Arizona among several states, which is typical of national companies, are held back for manual review rather than published. The methodology section below spells this out in full.

How often is it updated?

Monthly. The federal portal itself lags real events by design, because covered entities have up to 60 days to notify after discovering a breach and the portal is refreshed in batches, so checking more often than monthly surfaces very little that is new.

Can I use this data in an article or report?

Yes. The figures are drawn from public federal and open-source records, and we would ask that you cite this page and link back so readers can see the methodology and the source links for themselves. If you need a cut we do not publish here, such as a specific sector, city, or date range, get in touch and we will pull it.

Want to know where your organization would land on a list like this?

The pattern in the Arizona data is consistent: a server reached from outside, or an email account opened by someone who should not have had it. Tell us what you are running and we will tell you plainly whether you have a real gap or a manageable one.

Call (855) 737-9500 / (480) 573-3349

Email [email protected]

15-minute response on critical issues, 24/7. Onboarding in two to three weeks.

We reply within one business day. No spam, no pressure.