Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients

Arizona Arthritis and Rheumatology Associates · Healthcare · United States · March 3, 2025

People or records affected
5,509
5.5K as reported

What happened

Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.

How the deception worked

Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.

Sources (1)

  1. Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents
    HIPAA Journal·hipaajournal.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.