The Aligned Orthopedic Partners 2025 data breach involved unauthorized access to the email environment used by ASC Ortho Management Company, LLC under the Aligned Orthopedic Partners trade name. The organization said it identified unusual activity on December 8, 2025, and that an investigation found an unknown actor may have accessed certain emails and files between November 16 and December 16, 2025.
The U.S. Department of Health and Human Services Office for Civil Rights portal lists 7,213 affected people for ASC Ortho Management Company DBA Aligned Orthopedic Partners. The federal row classifies the event as an email-based Hacking/IT Incident. importedRecordCount is zero because no raw person-level data was obtained.
How Was the Aligned Orthopedic Incident Verified?
The primary source is the “Notice of Data Security Incident” PDF dated April 17, 2026 and hosted on Aligned Orthopedic's own alignedortho.com domain. It describes the access window, discovery date, outside investigation, completion of data review, possible information categories, notifications, and the 1-833-877-6247 assistance line.
The second source is the HHS/OCR federal row reported April 17, 2026 for 7,213 people. The third is ClaimDepot's incident summary using the same entity, dates, count, official PDF, and HHS link. The production duplicate search covered ASC Ortho, Aligned Orthopedic, the domain, likely slugs, and the incident period and found no matching record.
Incident Timeline
According to the official statement, an unauthorized person accessed Aligned Orthopedic's email environment from November 16 through December 16, 2025 and potentially viewed certain emails and files. breachDate and dateOccurred use November 16, the earliest known access date. The December end date alone does not prove continuous access.
dateDiscovered is December 8, 2025 because that is when the organization identified unusual activity. The investigation later established an access window ending December 16; the overlap between detection and the window's end is preserved. The affected-data review concluded February 17, 2026, and notification letters were mailed April 17.
What Information May Have Been Involved?
According to the official document, the combination varied by person and may include a name, date of birth, Social Security number, driver's license or state identification number, and financial account number. Medicaid or medicare numbers, patient account numbers, and medical record numbers are also among the listed identity and health fields.
Other health categories include dates of service, provider names, a mental or physical condition, medical treatment, diagnosis or clinical information, prescriptions, and health insurance information. The notice says the fields varied by individual; it should not be assumed that every category applied to all 7,213 people.
7,213 People Versus Zero Imports
7,213 is the affected-person total published in the HHS/OCR portal for the Aligned Orthopedic Partners event; it is not a number of emails, files, or medical-record rows. pwnCount and totalRecords equal this official person figure. Counts from other customers or facilities were not added.
importedRecordCount 0 means LeakData did not receive raw person-level records containing names, Social security numbers, financial accounts, or health information. The incident volume displayed to users is 7,213 people, while the number of searchable person-level records is zero. Zero imports do not mean no one was affected.
Identity, Health, and Financial Risks
A combination of Social Security, government ID, and financial account numbers can increase new-account fraud and account-takeover risk. Recipients can monitor financial activity and credit reports and consider a fraud alert or credit freeze when appropriate. Suspicious activity should be reported directly to the relevant institution.
Medicare or Medicaid, medical-record, diagnosis, treatment, prescription, and insurance information create medical identity-theft and privacy risks. Users should review insurance explanations for services they did not receive and unfamiliar claims. Eligible people may use Cyberscout identity-protection services; the stated enrollment deadline was July 16, 2026.
Organization Response and Steps for Individuals
Aligned Orthopedic said it took immediate steps to secure the network after identifying unusual activity, investigated with external cybersecurity experts, and augmented security to reduce the risk of a similar event. At the time of the official notice, it was not aware of misuse of potentially affected information.
People who did not receive a letter can call 1-833-877-6247 between 8:00 a.m. and 8:00 p.m. Eastern Time on weekdays to verify eligibility and ask questions. Users should rely on their individual letter for the specific data scope and protective steps. This record compares the official Aligned Orthopedic PDF, HHS/OCR row, and an independent incident summary.