Alta Orthopaedics Breach Impacts 24,496 Patients: PHI and PII Exposed

Published
August 21, 2026
Updated
August 21, 2026
Alta Orthopaedics Breach Impacts 24,496 Patients: PHI and PII Exposed
Alta Orthopaedics

Alta Orthopaedics Medical Group Inc, an orthopaedic medical practice serving California's Central Coast, disclosed a data breach affecting approximately 24,496 individuals in the United States.

On March 10, 2026, Alta Orthopaedics discovered unusual activity on its network and launched an investigation, according to the company's notification to consumers. The investigation determined that there had been unauthorized access to certain information stored on the company's network between Feb. 3, 2026, and Feb. 6, 2026.

Alta Orthopaedics then conducted a comprehensive review of the affected data to determine what types of information were involved and which individuals were affected. The company completed that review on June 24, 2026.

On March 9, 2026, a ransomware group known as INC Ransom posted on the dark web claiming to have obtained 26 gigabytes of data from Alta Orthopaedics. The group stated it intended to publish the data within four to five days.

The types of information potentially exposed included both personally identifiable information (PII) and protected health information (PHI).

The PII exposed included names, addresses, phone numbers, email addresses, Social Security numbers, driver's license or state ID numbers, other government ID numbers, passport numbers, dates of birth, financial account information and login information.

The PHI exposed included medical diagnoses, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, billing codes, prescription information, treatment locations, cost of treatment, health insurance information, health plan beneficiary numbers and biometric data.

The breach was disclosed attorneys general of California and Massachusetts. Alta Orthopaedics began notifying affected individuals in early July 2026. The company also posted a notice on its website.

Alta Orthopaedics' response to the breach

The company is offering affected individuals complimentary credit monitoring and identity protection services for 24 months through Cyberscout, a TransUnion company. Affected individuals can enroll by visiting Cyberscout's activation page and entering the unique code included in their notification letter. Enrollment must be completed within 90 days of the date of the letter.

Alta Orthopaedics has also set up a dedicated call center to answer questions about the incident. Affected individuals can call 1-877-424-8605, Monday through Friday between 5 a.m. and 5 p.m. PT, excluding major U.S. holidays.

Individuals can also write to the company at 511 Bath St., Santa Barbara, CA 93101.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Alta Orthopaedics
Consumers Notification date
Date of Breach
February 3, 2026 - February 6, 2026
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Social Security number
  • address
  • billing code
  • biometric data
  • clinical information
  • cost of treatment
  • date of birth
  • dates of service
  • driver’s license/state ID number
  • email address
  • financial account
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image