Prosthetic & Orthotic Care
Disclosed Aug 7, 201610 years ago23,015 affectedConfirmed
Prosthetic and Orthotics Care Inc. was hacked and PHI was either erased or encrypted with ransomware. The covered entity received a ransom note demanding $75,000 in bitcoins. This incident affected 23,015 individuals. Patient information included demographic information, names, and addresses, dates of birth, social security numbers, diagnosis/conditions, and treatment and claims information. Following the breach, the covered entity notified individuals, media, and the Department of Health and Human Services. The covered entity conducted an investigation to determine the root cause of the breach; contacted the FBI; and shut down the entire records system including MedFlex. Following these measures, the covered entity established stringent computer security guidelines, and retrained its staff in the new requirements intended to prevent a similar event from occurring in the future. The covered entity then cleaned and backed up pre-infiltration data files, installed new versions of Exchange Server and Office Suite, and installed a new MedFlex server. The covered entity also initiated upgrades to password length/complexity requirements, initiated multi-factor authentication for external
What is known
| People affected | 23,015 (as reported to HHS) |
|---|---|
| Disclosed | Aug 7, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Prosthetic & Orthotic Care (Healthcare Provider, MO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 7, 2016 | 23,015 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.