Blog > Data Breach & Privacy

Casper Orthopedics Data Breach: Wyoming Practice Discloses a Cyberattack

Casper Orthopedics, a Wyoming orthopedic practice, says a cyberattack it discovered in May 2026 may have exposed Social Security numbers, financial account details and medical information. Federal records list 56,197 people affected. Below, we walk through the notice and the steps patients can take.

Casper Orthopedics Data Breach: Wyoming Practice Discloses a Cyberattack

What Happened in the Casper Orthopedics Data Breach

A cyberattack discovered on or about May 23, 2026

Casper Orthopedic Associates, PC, known to patients as Casper Orthopedics, says it discovered on or about May 23, 2026, that it had been the victim of a cyberattack by an unauthorized third party. The practice says it immediately engaged outside cybersecurity experts to assess, contain and remediate the incident, and that law enforcement was notified.

According to the practice’s online notice, its investigation concluded on June 11, 2026, that the intruder may have acquired sensitive information from Casper’s systems. Separately, threat-intelligence firm DeXpose reported that the Anubis ransomware group claimed responsibility for an attack on Casper Orthopedics on July 12, 2026, in a statement saying patient data and medical records had been exposed. Casper has not named any group, and that claim has not been independently verified.

What Information May Have Been Involved

Social Security, license, bank and medical details

Casper’s notice lists the information potentially exposed as first and last name, date of birth, driver’s license number, Social Security number, financial account information, and medical information. The practice stresses that the affected data differed for each person and that not everyone had every element exposed.

That combination matters. A Social Security number paired with a birth date and driver’s license number can be used to open accounts in someone else’s name, financial account details carry a more immediate risk of unauthorized withdrawals, and medical information can be used to bill for care a patient never received. Casper says it has found no evidence that information in its care has been specifically misused.

Who May Be Affected by the Casper Orthopedics Breach

More than 56,000 people, according to HHS

Founded in 1976, Casper Orthopedics lists 10 physicians on its website along with physician assistants, nurse practitioners, therapists and athletic trainers. Its locations include a main clinic, a surgical center and two therapy centers, and its services run from sports medicine and joint replacement to physical therapy and imaging.

Casper reported the breach to the U.S. Department of Health and Human Services on July 23, 2026, and that federal listing shows 56,197 affected individuals in a hacking incident involving a network server. The practice’s notice refers broadly to individuals whose information may have been involved and does not say how many are patients, employees or others. As of this writing, the incident is not on the breach lists kept by the California, Vermont or Texas attorneys general, and it does not appear in Massachusetts’ 2026 breach report.

How Casper Orthopedics Responded to the Breach

Added safeguards, but no monitoring in its notice

Casper says it has implemented additional safeguards, improved its physical security related to cybersecurity, and continues working on its cybersecurity policies, procedures and protocols. Its online notice does not mention complimentary credit monitoring or identity protection, and instead refers readers to general fraud-prevention guidance.

Federal HIPAA rules call for notice to affected individuals without unreasonable delay and no later than 60 calendar days after a breach is discovered, unless law enforcement asks for a delay. Casper’s notice says it discovered the attack on or about May 23, 2026, that its investigation concluded on June 11, and that it finished identifying affected individuals and their addresses on September 2 before sending notices on September 8. The practice states that notification was not delayed by a law enforcement investigation.

Steps You Can Take to Protect Yourself

Self-help steps when no monitoring is offered

Because Casper’s notice describes no free monitoring service, patients may need to set up their own protections:

  • Place a credit freeze if your letter lists a Social Security or driver’s license number. Freezes at Equifax, Experian and TransUnion are free and can be lifted temporarily when you apply for credit.
  • Check the account tied to any financial information in your letter. Review recent statements for unfamiliar charges or withdrawals, since account fraud can surface faster than other identity theft.
  • Review Explanation of Benefits statements from your orthopedic visits. Look for surgeries, imaging, braces or therapy sessions you did not receive.
  • Consider an IRS Identity Protection PIN. With Social Security numbers and birth dates potentially exposed, a PIN makes it harder for someone else to file a tax return in your name.
  • Ignore unexpected requests that mention the cyberattack. Fraudsters often cite real incidents, so check any such message using contact details you look up yourself rather than ones included in the message.

This list is a starting point rather than legal advice. A legal professional can tell you which rights may be available given what your letter says.

Talk to Wilshire Law Firm

Did Casper Orthopedics send you a breach notice?

Did a September letter from Casper Orthopedics say your Social Security number, financial account or medical information may have been exposed? Wilshire Law Firm’s nationally recognized, award-winning team of data privacy lawyers can review what happened, including the timing of the notice and the absence of free monitoring, and explain whether a class action may be an option for affected patients. You can reach a legal professional 24/7 for free consultations and free case reviews, and there are no fees unless you get paid.

Contact Wilshire Law Firm to talk through your Casper Orthopedics notice with our team.

FAQs

The practice says it discovered the attack on or about May 23, 2026. Its investigation concluded on June 11, 2026, and notices went to affected individuals on September 8, 2026.

According to its notice, Casper spent the time after its investigation reviewing the affected information to identify the people involved and their addresses, a process it says was completed on September 2, 2026. The practice also states that its notification was not delayed by a law enforcement investigation.

The notice lists first and last name, date of birth, driver’s license number, Social Security number, financial account information, and medical information, with the exposed elements varying from person to person.

The practice’s report to the U.S. Department of Health and Human Services lists 56,197 affected individuals. Casper has not said how that total divides between patients and others.

Its online notice does not describe any complimentary credit monitoring or identity protection service. If your individual letter includes an offer, follow its enrollment instructions; otherwise, a credit freeze is a free protection you can set up yourself.

Threat-intelligence reporting says the Anubis ransomware group claimed responsibility for an attack on the practice on July 12, 2026, saying patient data and medical records had been exposed. Casper has not attributed the attack to any group, and the claim is unverified.

Possibly. The notice says Social Security numbers, financial account information and medical information may have been exposed, HHS lists more than 56,000 affected individuals, no free monitoring is described in the practice’s notice, and letters went out more than three months after the attack was discovered. Facts like these are often reviewed in class action investigations, though whether you have a claim depends on your own circumstances, which a free case review can help assess.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,526 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance