
Central Texas Paediatric Orthopaedics said it suffered a cyber security incident in January that compromised the sensitive personal information of more than 140,000 individuals.
Austin, Texas-based Central Texas Paediatric Orthopaedicsis a paediatric hospital dedicated for orthopaedic concerns. With a wide range of paediatric treatment options, it mainly focuses on the musculoskeletal health of children from birth to their twenties.
In a data security incident notice posted on its website, CTPO said that on January 25, it became aware of a security incident affecting its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities, including the FBI, about the incident.
“With assistance from a leading forensic security firm, we were able to determine that an unauthorised actor gained access to certain systems from January 23 - 26, 2025. On February 4, we discovered some of the accessed locations likely included patient information and limited information related to volunteers of CTPO,” reads the notice. The compromised data includes names, dates of birth, passports, and x-ray images.
The healthcare provider informed the Office of the Maine Attorney General in a regulatory filing that it identified at least 140,121 individuals who were impacted by the incident.
“We have worked diligently to determine how this incident happened and are taking appropriate measures to prevent a similar situation in the future. Since the incident we have implemented a series of cybersecurity enhancements, including installation of additional endpoint detection and response software, resetting all passwords, and rebuilding affected servers,” CTPO added.
The healthcare provider has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
In February, the Qilin ransomware group claimed responsibility for the cyber attack on CTPO and listed it as a victim on its data leak site. The group posted 42 GB of data stolen from the healthcare provider on the dark web that contained around 3,269 files, including several passport images.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543