[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faocogzyadhh7":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":13,"affectedCountUnit":25,"hasEnglishDescription":4,"contentLocale":26,"availableLocales":27,"translations":29,"severity":32,"dataClasses":33,"description":51,"seoTitle":52,"seoDescription":53,"logoUrl":54,"isVerified":4,"isSensitive":4,"isSpamList":55,"isMalware":55,"company":56},"6a4ce187787ae1e3e8ce5f47","Western Orthopaedics","Western Orthopaedics Data Breach","western-orthopaedics","western-ortho.com","2025-09-17T00:00:00.000Z","2026-07-07T11:22:47.402Z",null,"2026-07-19T00:10:16.829Z","Manual reviewed breach record","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-684-western-orthopaedics-pc\u002Fdownload",[16,18,19,20,21,22],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf","https:\u002F\u002Fwww.hipaajournal.com\u002Fdata-breaches-four-healthcare-providers-may-2026\u002F","https:\u002F\u002Fwww.classaction.org\u002Fdata-breach-lawsuits\u002Fwestern-orthopaedics-may-2026","https:\u002F\u002Fwww.western-ortho.com\u002F","https:\u002F\u002Fwww.western-ortho.com\u002Fcontactus",113330,"known","unknown","en",[26,28],"tr",{"en":30,"tr":31},{"slug":9},{"slug":9},"High",[34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50],"Names","Physical addresses","Phone numbers","Social security numbers","Dates of birth","Passwords","Financial account information","Credit and debit card information","Payment card security codes","Payment card access codes","Health insurance information","Health insurance plan or subscriber identification numbers","Provider names","Dates of service","Medical cost information","Billing information","Protected health information","\u003Cp>The Western Orthopaedics data breach is related to an unauthorized access and data acquisition incident that occurred on the network of the Colorado-based orthopedic healthcare organization between September 17, 2025, and September 25, 2025. Publicly available notices indicate that the organization became aware of the incident around October 2, 2025, file review was completed around March 3, 2026, and affected individuals were notified in May 2026. Official health breach records list the number of affected individuals as 113,330, so this record was published with the confirmed total scope. The 193,000-row volume seen in leak indexes has been evaluated separately.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The breach contained personal information such as full name, physical address, phone number, Social Security number, date of birth, financial account information, credit or debit card numbers, security code or access code in payment areas, health insurance information, and health data related to medical services. The scope of medical data may include fields such as health insurance plan or subscriber number, medical service provider name, service dates, medical cost, and billing information. This combination poses a high risk of identity theft, payment card misuse, health insurance fraud, false billing notifications, and targeted phishing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The verified person coverage for Western Orthopaedics is 113,330 individuals. In contrast, 193,000 rows appear in the leak indexes; this value should not be interpreted as the number of unique individuals. A person's phone, address, payment, or healthcare service rows may appear as separate records or there may be duplicates associated with the same person. Therefore, the grand total shown to the user is determined according to the official person coverage, while the row volume is kept separately as the internal record count. The start of the access range, September 17, 2025, was used as the incident date. September 25, 2025, is the end of the access range, October 2, 2025, is the date of discovery, and March 3, 2026, should be considered the stage when the analysis of the affected files was completed.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk group includes current and former patients of Western Orthopaedics who have undergone examinations, surgical procedures, orthopedic treatments, imaging, insurance approvals, billing, or payment processes. Social Security numbers, birth dates, and addresses of affected individuals should be particularly monitored against credit and identity theft. Financial account or payment card information requires affected users to regularly review their bank and card transactions. Those with health insurance and medical service information should check statement documents for any records of unrecognized treatments, services, devices, providers, costs, or bills. Phone numbers and address information can facilitate attackers in preparing convincing calls and messages related to orthopedic treatment or payments.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users whose information was matched in this breach should first check password security on their patient portal, health insurance account, and financial accounts. Accounts using the same password should be separated, and additional verification steps should be enabled. Individuals whose Social Security numbers may have been affected should review their credit reports and immediately initiate a dispute process if they see new accounts or unrecognized inquiries. If necessary, credit freeze or fraud alert options should be considered. People with payment card or financial account information should closely monitor bank and card transactions and contact the card issuer or bank directly in case of unrecognized activity.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Since this breach contains identity, financial, and health data, it requires long-term monitoring. Users should keep notifications on in health service accounts, regularly review insurance explanation documents, and archive medical bills or reimbursement notices. In requests received by phone for payment, appointments, medical devices, insurance approvals, or debt collection, the caller's identity should be verified before sharing personal data. Transaction alerts should be kept on in financial accounts, and options for card renewal or account monitoring should be considered. Sensitive documents related to health services should be stored securely; Social Security numbers, birth dates, insurance plans, and payment information should not be shared in the same message.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>A match in LeakData for Western Orthopaedics data breach control indicates that the individual may be part of this breach record group and requires multi-faceted security action. Users who have a match should not only change their password; they should simultaneously check their credit reports, bank and card transactions, insurance explanation documents, and patient portal activities. The absence of a match does not necessarily mean no risk; some notifications may have been sent by mail, or the leaked records may not match the individual exactly. It is recommended that individuals who have previously received services from this healthcare institution keep official notifications and contact the relevant institution through known communication channels if they observe suspicious financial or medical activity.\u003C\u002Fp>","Western Orthopaedics Data Breach (113.3 Thousand Reported Records)","Western Orthopaedics Data Breach. 113.3 Thousand reported records are reported. Reported data: Names, Physical addresses, Phone numbers. Review the scope…","\u002Fuploads\u002Flogo\u002Fwestern-orthopaedics.png",false,{"name":57,"sector":58,"country":59,"website":10,"websiteArchiveUrl":60,"websiteStatus":60,"websiteCheckedAt":13},"Western Orthopaedics, P.C.","Healthcare","United States",""]