The Excelsior Orthopaedics 2024 data breach involved the New York healthcare provider detecting unusual network activity on June 23, 2024 and confirming that data associated with current and former patients and employees had been compromised. The scope included information held by Excelsior and related entities Buffalo Surgery Center and Northtowns Orthopaedics.
An updated official filing with the Maine Attorney General increased the nationwide affected population from 357,000 to 394,752. An earlier HHS healthcare report dated August 21, 2024 lists 292,913 people, so this LeakData record uses the later overall total instead of that earlier subset. importedRecordCount is zero because no person-level data was imported.
How Was the Excelsior Orthopaedics Breach Confirmed?
The primary source is the amended notice in the Maine Attorney General's official portal. Its linked letter documents the June 23 discovery, initial forensic findings, patient and employee scope, notification waves, and the organization's response. The later amended filing raises the previously reported overall population to 394,752 people.
The second source is the official HHS Office for Civil Rights breach portal, where the Excelsior Orthopaedics row reports 292,913 people affected by a network-server hacking/IT incident on August 21, 2024. ClaimDepot independently reconciles the amended Maine filing and September 2025 state notices, documenting the current overall total and exposed data classes.
What Happened on June 23, 2024?
Excelsior identified unusual activity in its network on June 23. The provider disconnected external network access, isolated suspect equipment, changed user and administrative credentials, and engaged a specialist cybersecurity firm for a forensic investigation. Initial results showed that data concerning current and former patients and employees had been compromised.
Excelsior then worked with outside data-review specialists to associate the compromised files with individuals. A small initial group received notices in August 2024; after the bulk of data mining finished in December, a second wave of letters was mailed December 31. Public records do not identify the initial-entry method, exploited vulnerability, or threat actor.
What Identity and Employee Information Was Involved?
Core fields that varied by individual were full names, addresses, dates of birth, Social security numbers, driver's license numbers, or non-driver identification card numbers. Biometric information was also listed in the employee sample. The record does not assume that every recipient had every field involved; an individual's own notice defines that person's scope.
An SSN combined with a birth date and government identification number can increase the risk of new-account fraud, impersonation, or persuasive phishing. “Biometric information” appears as a broad category in the official sample. Because the provider did not specify its form, this record does not infer a face template, fingerprint, or any other unreported subtype.
What Medical and Insurance Data Was Involved?
Potential patient fields were medical record numbers, diagnoses and diagnosis codes, treatment locations, procedure types, provider names, treatment costs, and dates of service. Health insurance information, subscriber or member numbers, and patient account numbers were also listed. These fields can make healthcare, billing, and benefits scams more convincing.
Notice recipients can inspect explanations of benefits, patient-portal activity, unfamiliar services, unexpected collection attempts, and provider messages. A communication is not trustworthy merely because it includes a real diagnosis, service date, or provider name. Verify it separately through a known provider telephone number or the established patient portal.
How Should the 394,752 Figure Be Interpreted?
The 394,752 figure is the most recent nationwide total in the amended Maine Attorney General record. The earlier 357,000 disclosure and the 292,913 HHS figure reflect reviews and notification scopes completed at different times; they must not be added together. pwnCount and totalRecords are 394,752, while importedRecordCount remains zero because LeakData holds no raw person-level records.
The official Maine letter said in January 2025 that work to identify affected people was ongoing, and the later amended filing increased the population. This entry therefore uses the latest published whole number instead of labeling an earlier report as final. State resident subtotals are not added to the nationwide figure, preventing double counting.
How Did Excelsior Respond and What Should Recipients Do?
Excelsior contained the network, changed credentials, and reported deploying new security tools, redesigning key systems and business processes, and strengthening security awareness and alerts. It reported the incident to the FBI. The Maine sample offered affected people 12 months of complimentary credit monitoring and identity-theft restoration through CyberScout.
A recipient should confirm the enrollment deadline in their own letter and consider a credit freeze, fraud alert, and new-account monitoring if an SSN or identification number was involved. For health data, review benefits statements and patient accounts. Do not share a password, full SSN, payment, or one-time code in an unexpected message using the Excelsior name.