A-O-M-S, P.L.L.C. d/b/a Arkansas Oral & Maxillofacial Surgeons Data Breach Investigation

Data Breach Blog

Data Breach

A-O-M-S, P.L.L.C. d/b/a Arkansas Oral & Maxillofacial Surgeons Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

September 8, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at A-O-M-S, P.L.L.C. d/b/a Arkansas Oral & Maxillofacial Surgeons. If you were affected, contact Almeida Law Group.

About A-O-M-S, P.L.L.C. d/b/a Arkansas Oral & Maxillofacial Surgeons

Arkansas Oral & Maxillofacial Surgeons (AOMS) is a specialty dental and surgical practice based in Hot Springs, Arkansas, with additional locations in Conway, Russellville, and Fort Smith. The practice provides oral and maxillofacial procedures including tooth extractions, dental implants, corrective jaw surgery, cosmetic dentistry services, and treatment of facial injuries. Because AOMS treats patients, it collects and stores detailed personal, medical, and financial information as part of providing care.

What Happened?

AOMS was listed in an HHS Office for Civil Rights breach portal report as a hacking/IT incident affecting a network server. On April 7th, 2026, AOMS detected potential unauthorized access to its computer systems. The practice’s investigation confirmed on June 2nd, 2026 that an unauthorized third party had accessed the network and exfiltrated files containing patient information. According to AOMS’s own breach notification, as reported by HIPAA Journal and Medical Buyer, the exfiltrated files contained names, contact information, dates of birth, medical record numbers, government identification numbers including Social Security numbers, diagnosis information, treatment records, health insurance information, prescription histories, and payment information. AOMS began notifying affected individuals by mail in August 2026 and reported the breach to the HHS Office for Civil Rights on July 31st, 2026, with 64,831 individuals listed as affected. AOMS is offering affected individuals complimentary credit monitoring, health information monitoring, and identity theft protection services through CyEx.

The PEAR ransomware group has claimed responsibility for the attack and on April 10th, 2026 posted on the dark web claiming to have obtained 2.1 terabytes of data. These are attacker-side allegations and have not been publicly confirmed by AOMS. HIPAA Journal characterized the incident as a data theft and extortion attempt. As of August 2026, at least two law firms — Mason LLP and Poynter Law Group — have announced class action investigations, though no filed complaints have been confirmed.

Key Facts at a Glance

  • Company or Organization: A-O-M-S, P.L.L.C. d/b/a Arkansas Oral & Maxillofacial Surgeons
  • Industry: Healthcare Provider — Oral and Maxillofacial Surgery / Dental
  • Location: Hot Springs, Arkansas (with additional locations in Conway, Russellville, and Fort Smith, AR)
  • Incident type: Hacking/IT Incident — Network Server
  • Date of breach: April 7th, 2026
  • Date breach discovered: June 2nd, 2026
  • Date of consumer notification: August 2026
  • Total persons affected: 64,831
  • Identity theft protection offered: Yes — credit monitoring, health information monitoring, and identity theft protection through CyEx
  • Litigation status: Class action investigations announced by Mason LLP and Poynter Law Group (as of August 2026); no filed complaints confirmed
  • Source: HHS OCR Breach Portal; HIPAA Journal; ClaimDepot; Poynter Law Group Press Release; Mason LLP

What Should You Do?

If you received a notice from Arkansas Oral & Maxillofacial Surgeons, enroll in the complimentary identity protection services through CyEx as soon as possible and note any enrollment deadline included in your notice. Place fraud alerts or credit freezes with the three major credit bureaus — Equifax, Experian, and TransUnion — and review your credit reports for unfamiliar accounts or activity at AnnualCreditReport.com. Because health and medical information was involved, carefully review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive. Report any signs of identity theft or fraud to IdentityTheft.gov.

Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.