Arizona Health Advantage, Inc. d/b/a Arizona Priority Care; AZPC Clinics, LLC; and the health plans for which APC has executed a BAA, listed below Data Breach
Arizona Priority Care Network Server Breach Affects 10,978
What happened in the Arizona Health Advantage, Inc. d/b/a Arizona Priority Care; AZPC Clinics, LLC; and the health plans for which APC has executed a BAA, listed below data breach?
The Arizona Health Advantage, Inc. d/b/a Arizona Priority Care; AZPC Clinics, LLC; and the health plans for which APC has executed a BAA, listed below data breach was reported on February 1, 2023 and affected 10,978 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Arizona. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Arizona Health Advantage, Inc. d/b/a Arizona Priority Care; AZPC Clinics, LLC; and the health plans for which APC has executed a BAA, listed below Breach Details
Arizona Priority Care Network Server Breach Report
Incident Overview
Arizona Health Advantage, Inc., operating under the names Arizona Priority Care (APC) and AZPC Clinics, LLC, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on February 1, 2023, affecting 10,978 individuals. The incident involved a hacking or IT-related compromise of the organization's network server, which typically serves as a central repository for patient health information, billing records, and administrative data across the healthcare provider's operations.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach notification submission, though the entity filed its mandatory HIPAA breach notification report on February 1, 2023. Upon discovery of the unauthorized access, Arizona Priority Care initiated an investigation to determine the scope of the breach, identify affected individuals, and assess what protected health information (PHI) may have been compromised. The organization's response included notification procedures required under the HIPAA Breach Notification Rule, which mandates that covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. The entity also notified relevant health plans for which Arizona Priority Care had executed Business Associate Agreements (BAAs), ensuring transparency across the healthcare ecosystem.
Technical Details of the Breach
The breach occurred at the network server level, which represents a significant vulnerability point in healthcare IT infrastructure. Network servers typically store consolidated patient records, electronic health information (EHI), billing data, and administrative files accessible across an organization's systems. Unauthorized access to such infrastructure suggests either a compromise of network security controls, exploitation of software vulnerabilities, credential theft, or other IT security failures. Hacking incidents of this nature often involve techniques such as exploitation of unpatched systems, weak authentication mechanisms, phishing attacks leading to credential compromise, or direct network intrusion. The fact that this breach affected a substantial number of individuals (10,978) indicates the server likely contained centralized data repositories rather than isolated departmental systems. The breach notification does not specify the exact attack vector, but network server compromises typically require investigation of firewall logs, intrusion detection systems, access controls, and system audit trails to determine how unauthorized access was achieved and what data was accessed.
Organizational Context
Arizona Priority Care operates as a healthcare provider organization in Arizona, offering clinical services through AZPC Clinics and health plan administration through Arizona Health Advantage, Inc. The organization's structure—with multiple operating entities and relationships with health plans through Business Associate Agreements—indicates a mid-sized healthcare operation with both direct patient care delivery and health plan management functions. The organization serves the Arizona market and maintains relationships with multiple health plans, suggesting a regional healthcare provider with significant operational scope. The involvement of multiple legal entities (Arizona Health Advantage, Inc. and AZPC Clinics, LLC) indicates a complex organizational structure typical of integrated healthcare delivery and financing organizations.
Impact on Affected Individuals
Approximately 10,978 individuals had their protected health information potentially exposed through the network server breach. This population likely includes current and former patients of AZPC Clinics as well as members of health plans administered by Arizona Health Advantage, Inc. The breach notification requirement under HIPAA mandates that all affected individuals be notified of the breach, the types of information involved, steps the organization is taking to investigate and mitigate the breach, and recommended actions individuals should take to protect themselves. Notification typically occurs through written communication sent to the last known address on file, with additional notification methods potentially including email or telephone contact. The 60-day notification window from discovery means affected individuals should have received formal notification by early April 2023, though some individuals may not have received timely notice if contact information was outdated.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA's Security Rule, which requires covered entities to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Network server security is a critical component of HIPAA compliance, requiring measures such as access controls, encryption, audit controls, and integrity controls. The breach notification to HHS indicates that Arizona Priority Care determined the breach involved unsecured PHI, meaning the information was not rendered unusable through encryption or destruction. Network server breaches are among the most common sources of healthcare data breaches, accounting for a significant percentage of reported incidents in the healthcare industry. According to HHS breach notification data, hacking and IT incidents represent a leading cause of healthcare data breaches, often affecting larger numbers of individuals than other breach types due to the centralized nature of server-based data storage. The fact that no Business Associate was involved in this breach indicates the compromise occurred within Arizona Priority Care's own systems rather than through a third-party vendor relationship, placing full responsibility for the breach response and remediation on the organization itself.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Arizona Health Advantage, Inc. d/b/a Arizona Priority Care; AZPC Clinics, LLC; and the health plans for which APC has executed a BAA, listed below Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized services, claims, or providers; contact your health plan and providers immediately if you identify suspicious activity
Monitor your health insurance accounts for unauthorized access; change passwords for any online health plan portals and use strong, unique passwords
Consider enrolling in credit monitoring and identity theft protection services if offered by Arizona Priority Care; watch for suspicious communications claiming to be from healthcare providers or insurers requesting personal information
Be cautious of unsolicited phone calls, emails, or mail requesting medical information or offering medical services; verify any communications directly with known provider phone numbers
Request a copy of your medical records from Arizona Priority Care to verify accuracy and identify any unauthorized access or modifications
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you suspect identity theft or fraudulent activity related to this breach
Consider placing a security freeze with credit bureaus to prevent unauthorized credit inquiries, and monitor your Social Security number usage through the Social Security Administration's online account
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Arizona Breaches
Search all breaches reported in Arizona
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits