Skip to content

Centers for Advanced Orthopaedics

Disclosed Mar 25, 20215 years ago125,291 affectedConfirmed

Official notice

The Centers for Advanced Orthopaedics, the covered entity (CE), reported that it experienced a ransomware incident that affected the protected health information (PHI) of 21,162 individuals. The PHI involved included names, dates of birth, Social Security numbers, drivers’ license numbers, passport numbers, diagnoses, financial information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. All staff were retrained.

What is known

People affected125,291 (as reported to HHS)
DisclosedMar 25, 2021
HappenedSep 10, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 25, 2021125,291
HHS archivetotalNov 11, 202121,162
Indiana AGresidents of INApr 12, 20221
History of this record
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 21162 to 125291 · backfill source
  • 2026-09-25 · disclosed: 2021-11-11 to 2021-03-25 · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2022-04-12 to 2021-11-11 · backfill source
  • 2026-09-25 · summary: empty to The Centers for Advanced Orthopaedics, the covered entity (CE), reported that it experienced a ransomware incident that affected the protected health information (PHI) of 21,162 individuals. The PHI involved included names, dates of birth, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Centers for Advanced Orthopaedics

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.