← Alta Orthopaedics

2026 Alta Orthopaedics — Feb 3–6 network access; 24,496 patients; INC Ransom claimed (PHI/SSNs)

2026 24.5K records affected Share on X

Data compromised

Names, contact info, SSNs, driver’s license/state IDs, other government IDs, passports, financial accounts, DOBs, login credentials; PHI including diagnoses, treatment, clinical/MRN/account numbers, prescriptions, billing codes, health insurance, and biometric data

Technical writeup

Verified practice notification summarized by HIPAA Journal — September 3, 2026. Alta Orthopaedics (Santa Barbara/Solvang/Santa Maria/Oxnard, CA) identified unusual network activity March 10, 2026; investigation found unauthorized access February 3–6, 2026, with data review completed June 24, 2026. The practice notified 24,496 individuals and offered 24 months of credit monitoring. Exposed categories include broad PII (SSNs, DLs, passports, financial accounts, login credentials) and extensive PHI (diagnoses, treatment, clinical identifiers, prescriptions, insurance, biometric data). INC Ransom claimed responsibility and said ~26 GB was exfiltrated and later leaked; the company notice did not name the group. recordsAffected 24496 from company notification via HIPAA Journal; companyConfirmed true.

Root cause

Unauthorized third-party access to Alta Orthopaedics network February 3–6, 2026; unusual activity identified March 10; INC Ransom later claimed exfiltration of ~26 GB

References