[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fa2jxpvhv8mdm":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"6a705581b83b01981cc18c8e","ConcordOrthopaedics2024","Concord Orthopaedics 2024 Data Breach","concord-orthopaedics-2024","concordortho.com","2024-11-21T00:00:00.000Z","2026-08-03T08:46:57.392Z","Official organization notice, HHS OCR report, and independent notice-based reporting","https:\u002F\u002Fwww.concordortho.com\u002Fstorage\u002Fcomponents\u002Fclearwave_databreach_websitenotice_1.pdf",[14,16,17,18],"https:\u002F\u002Fstraussborrelli.com\u002F2025\u002F03\u002F26\u002Fconcord-orthopaedics-data-breach-investigation\u002F","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf","https:\u002F\u002Fwww.concordortho.com\u002F",72815,"known",null,"people","Medium",[25,26,27,28,29,30],"Names","Dates of birth","Social security numbers","Driver's license or state identification numbers","Appointment information","Health insurance information","\u003Cp>\u003Cstrong>The 2024 Concord Orthopaedics data breach\u003C\u002Fstrong> involved unauthorized access to third-party software used by the New Hampshire orthopaedic practice for patient registration and appointment intake. The organization was notified of the incident on November 21, 2024, shut down access to the software, and reset its passwords.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a Hacking\u002FIT Incident affecting 72,815 people. Concord Orthopaedics' investigation found that patient registration and appointment information in the third-party system may have been viewed or acquired; it found no evidence that the organization's own electronic health record environment was compromised.\u003C\u002Fp>\u003Ch2>How was the Concord Orthopaedics breach confirmed?\u003C\u002Fh2>\u003Cp>The organization's official notice connects Concord Orthopaedics, the third-party patient-registration software, the November 21, 2024 notification date, and the potentially affected data types in one event. The HHS OCR entry also confirms the organization, the total of 72,815 people, and the March 25, 2025 report date.\u003C\u002Fp>\u003Cp>Independent incident reviews tie the details in the official notice and the regulatory total of 72,815 to the same breach. Public sources do not disclose the exact beginning or end of the unauthorized access, so November 21 is treated here as the date the organization was notified, not as a claimed exact attack date.\u003C\u002Fp>\u003Ch2>What happened in November 2024?\u003C\u002Fh2>\u003Cp>On November 21, Concord Orthopaedics learned that an unauthorized person may have accessed third-party software used to register patients and prospective patients and check them in for appointments. The organization disabled access, reset passwords for the software, and engaged external cybersecurity specialists to investigate the nature of the event.\u003C\u002Fp>\u003Cp>The investigation found that the unauthorized party accessed the software and may have viewed or acquired registration and appointment-intake information stored there. It found no evidence of compromise to Concord Orthopaedics' internal environment or electronic health record system, which was hosted in a separate application.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, the information may have included names, dates of birth, Social Security numbers, driver's license or state identification numbers, and images of identity documents for some people. Disclosed appointment data included appointment type, physician name, and the date and location of an appointment.\u003C\u002Fp>\u003Cp>Health insurance fields could include a health plan beneficiary number, health plan number, and insurance eligibility information. Email addresses, passwords, payment cards, and bank accounts are not included in this record because the official incident notice does not confirm those fields.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity numbers combined with healthcare appointment and insurance details can increase the risk of identity theft, fraudulent insurance claims, and targeted scams. Social Security and driver's license numbers are difficult to change, so misuse may surface long after the original event.\u003C\u002Fp>\u003Cp>Someone who knows a real appointment type, physician name, or insurance detail may craft a convincing message. Possessing those details does not prove that a caller represents Concord Orthopaedics, a physician, or an insurer, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Concord Orthopaedics disabled access to the third-party software, reset passwords, investigated with external cybersecurity specialists, and notified federal law enforcement. The organization also said it was reviewing practices and policies concerning third-party vendors.\u003C\u002Fp>\u003Cp>Affected people were notified, and eligible individuals were offered identity-protection services. The official notice confirms only the event involving the third-party registration software; it does not disclose the initial access method, a technical vulnerability, or the precise access window.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>People who received a notice should regularly review credit reports, financial accounts, and health insurance explanations for unfamiliar accounts, transactions, appointments, or claims. Suspicious entries should be reported to the relevant financial institution, health insurer, and appropriate authorities when necessary.\u003C\u002Fp>\u003Cp>Social Security numbers, insurance information, passwords, and one-time verification codes should not be shared in unexpected emails, messages, or calls. A request claiming to come from Concord Orthopaedics should be verified using contact information on the official website rather than a link or phone number in the message.\u003C\u002Fp>","","Concord Orthopaedics 2024 Data Breach (72.8 Thousand People Affected)","The Concord Orthopaedics breach may have exposed identity, appointment, and health insurance data belonging to 72,815 people.","\u002Fuploads\u002Flogo\u002Fconcord-orthopaedics-official.jpg",false,{"name":38,"sector":39,"country":40,"website":18,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Concord Orthopaedics","Healthcare","United States"]