2026 Alta Orthopaedics — unauthorized network access Feb 3–6; patient PHI notices
Data compromised
Names, addresses, phones, SSNs, driver’s license/state IDs, DOB, billing codes, dates of service, visit reasons, treatment costs, provider names, diagnoses/treatment/clinical info, location, MRNs, account numbers, health insurance — aggregate count unpublished
Technical writeup
Verified orthopedics-practice disclosure — HIPAA Journal coverage July 2026. Alta Orthopaedics (Santa Barbara, CA; six locations) identified suspicious activity March 10, 2026. Forensics determined unauthorized access to certain network information between February 3 and February 6, 2026. Exposed files held PHI including names, addresses, phones, SSNs, driver’s license/state IDs, birth dates, billing codes, dates of service, reasons for visits, treatment costs, provider names, diagnoses, treatment and clinical information, treatment location, medical record and patient account numbers, and health insurance information. Law enforcement notified; complimentary credit monitoring offered. Aggregate headcount not yet publicly disclosed. recordsAffected 0 pending OCR/state AG tally.
Root cause
Unauthorized access to certain network information Feb 3–6, 2026 (detected Mar 10)