
New York-based orthopaedic firm Northeast Orthopedics & Sports Medicine said it experienced a significant data security incident last year that compromised the sensitive personal information of close to 180,000 individuals.
Northeast Orthopedics & Sports Medicine operates nine clinics in New York and provides comprehensive care for orthopaedic conditions such as ACL tears, carpal tunnel syndrome, sciatica and fractures.
In a recent data breach incident notice filed with the Office of the Maine Attorney, Northeast Orthopaedics said that on November 22, it identified suspicious unauthorised activities in its internal network and immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident.
“On December 29, 2023 the investigation determined an unauthorised party may have accessed certain files on our network for a limited period of time. Therefore, we began a thorough review of the potentially impacted portions of our network to determine the type of information contained therein and to whom the information related. Northeast Orthopaedics completed its review on February 8, 2024 and determined information related to you was potentially impacted,” reads the notice.
In a similar data security incident notice posted on its website, the healthcare firm said that the compromised data included patients’ name, Social Security numbers, drivers license information, payment information, dates of birth, medical record information, health insurance information, and treatment and diagnosis information.
In its filing with the Office of the Maine Attorney General, the firm added that financial account numbers, credit and debit card numbers along with security codes, access codes, passwords and PINs were also accessed by the threat actor. It added that the data security incident compromised the personal and financial information of at least 177,276 individuals.
“In response to this incident, we also worked with third-party specialists to re-secure our network, implement additional precautions, and we are reviewing our policies and procedures related to data protection,” it added.
While Northeast Orthopaedics did not find any evidence of the compromised data being misused, the possibility for the same cannot be ruled out. The company has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.
It is also offering complimentary credit monitoring and identity theft protection services through Epiq to all the individuals affected by the data breach. It has also set up a dedicated helpline where affected individuals can call and get their queries resolved.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543