2026 Alta Orthopaedics — Feb 3–6 network access; 24,496 patients; INC Ransom claimed (PHI/SSNs)
Data compromised
Names, contact info, SSNs, driver’s license/state IDs, other government IDs, passports, financial accounts, DOBs, login credentials; PHI including diagnoses, treatment, clinical/MRN/account numbers, prescriptions, billing codes, health insurance, and biometric data
Technical writeup
Verified practice notification summarized by HIPAA Journal — September 3, 2026. Alta Orthopaedics (Santa Barbara/Solvang/Santa Maria/Oxnard, CA) identified unusual network activity March 10, 2026; investigation found unauthorized access February 3–6, 2026, with data review completed June 24, 2026. The practice notified 24,496 individuals and offered 24 months of credit monitoring. Exposed categories include broad PII (SSNs, DLs, passports, financial accounts, login credentials) and extensive PHI (diagnoses, treatment, clinical identifiers, prescriptions, insurance, biometric data). INC Ransom claimed responsibility and said ~26 GB was exfiltrated and later leaked; the company notice did not name the group. recordsAffected 24496 from company notification via HIPAA Journal; companyConfirmed true.
Root cause
Unauthorized third-party access to Alta Orthopaedics network February 3–6, 2026; unusual activity identified March 10; INC Ransom later claimed exfiltration of ~26 GB