Skip to content

Prosthetic & Orthotic Care

Disclosed Aug 7, 201610 years ago23,015 affectedConfirmed

Official notice

Prosthetic and Orthotics Care Inc. was hacked and PHI was either erased or encrypted with ransomware. The covered entity received a ransom note demanding $75,000 in bitcoins. This incident affected 23,015 individuals. Patient information included demographic information, names, and addresses, dates of birth, social security numbers, diagnosis/conditions, and treatment and claims information. Following the breach, the covered entity notified individuals, media, and the Department of Health and Human Services. The covered entity conducted an investigation to determine the root cause of the breach; contacted the FBI; and shut down the entire records system including MedFlex. Following these measures, the covered entity established stringent computer security guidelines, and retrained its staff in the new requirements intended to prevent a similar event from occurring in the future. The covered entity then cleaned and backed up pre-infiltration data files, installed new versions of Exchange Server and Office Suite, and installed a new MedFlex server. The covered entity also initiated upgrades to password length/complexity requirements, initiated multi-factor authentication for external

What is known

People affected23,015 (as reported to HHS)
DisclosedAug 7, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalAug 7, 201623,015
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Prosthetic & Orthotic Care

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.