Integrated Orthopedics of Arizona experienced a major data breach. The cybersecurity incident resulted in the exposure of both personally identifiable information (PII) and protected health information (PHI).
On or around April 7, 2025, IOA became aware of suspicious activity within its internal email environment. An investigation determined that some emails may have been copied without authorization.
A review was completed on June 19, 2025. Exposed information includes names, addresses, dates of birth, driver’s license numbers, Social Security numbers, medical record numbers, patient ID or account numbers, Medicare numbers, Medicaid numbers, health insurance ID Numbers, health insurance group numbers, medical diagnosis Information, medical treatment information, medical treatment location, doctor name, medical treatment dates and medical lab or test results .
The total number of impacted individuals has not been released, but could include several thousand current and former patients. Integrated Orthopedics of Arizona published a Notice of Data Event on its website and began notifying impacted individuals on Aug. 11, 2025.
Integrated Orthopedics of Arizona disclosed the data breach to the Massachusetts Attorney General's office on Aug. 15, 2025. The nature of the cybersecurity incident exposed increases the risk for affected individuals, as Social Security numbers and detailed medical information can be used for identity theft and fraudulent financial transactions.
In addition to required state and federal disclosures, Integrated Orthopedics of Arizona is offering affected patients 24 months of credit monitoring and identity theft restoration services.
If you received a notice or believe your personal and protected health information may have been compromised in this breach:
For more information about the healthcare organization, visit the Integrated Orthopedics of Arizona website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.