- State
- AR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,916
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Arkansas Methodist Medical Center, reported that its financial institution notified them that it had experienced a cyber-attack that affected the electronic protected health information (ePHI) of 4,916 individuals. OCR determined that the financial institution was not a business associate as defined by HIPAA and is therefore, not subject to the HIPAA Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.