Data Breach & Privacy
Blog > Data Breach & Privacy
Casper Orthopedics Data Breach: Wyoming Practice Discloses a Cyberattack
Casper Orthopedics, a Wyoming orthopedic practice, says a cyberattack it discovered in May 2026 may have exposed Social Security numbers, financial account details and medical information. Federal records list 56,197 people affected. Below, we walk through the notice and the steps patients can take.

What Happened in the Casper Orthopedics Data Breach
A cyberattack discovered on or about May 23, 2026
Casper Orthopedic Associates, PC, known to patients as Casper Orthopedics, says it discovered on or about May 23, 2026, that it had been the victim of a cyberattack by an unauthorized third party. The practice says it immediately engaged outside cybersecurity experts to assess, contain and remediate the incident, and that law enforcement was notified.
According to the practice’s online notice, its investigation concluded on June 11, 2026, that the intruder may have acquired sensitive information from Casper’s systems. Separately, threat-intelligence firm DeXpose reported that the Anubis ransomware group claimed responsibility for an attack on Casper Orthopedics on July 12, 2026, in a statement saying patient data and medical records had been exposed. Casper has not named any group, and that claim has not been independently verified.
Who May Be Affected by the Casper Orthopedics Breach
More than 56,000 people, according to HHS
Founded in 1976, Casper Orthopedics lists 10 physicians on its website along with physician assistants, nurse practitioners, therapists and athletic trainers. Its locations include a main clinic, a surgical center and two therapy centers, and its services run from sports medicine and joint replacement to physical therapy and imaging.
Casper reported the breach to the U.S. Department of Health and Human Services on July 23, 2026, and that federal listing shows 56,197 affected individuals in a hacking incident involving a network server. The practice’s notice refers broadly to individuals whose information may have been involved and does not say how many are patients, employees or others. As of this writing, the incident is not on the breach lists kept by the California, Vermont or Texas attorneys general, and it does not appear in Massachusetts’ 2026 breach report.
How Casper Orthopedics Responded to the Breach
Added safeguards, but no monitoring in its notice
Casper says it has implemented additional safeguards, improved its physical security related to cybersecurity, and continues working on its cybersecurity policies, procedures and protocols. Its online notice does not mention complimentary credit monitoring or identity protection, and instead refers readers to general fraud-prevention guidance.
Federal HIPAA rules call for notice to affected individuals without unreasonable delay and no later than 60 calendar days after a breach is discovered, unless law enforcement asks for a delay. Casper’s notice says it discovered the attack on or about May 23, 2026, that its investigation concluded on June 11, and that it finished identifying affected individuals and their addresses on September 2 before sending notices on September 8. The practice states that notification was not delayed by a law enforcement investigation.
Steps You Can Take to Protect Yourself
Self-help steps when no monitoring is offered
Because Casper’s notice describes no free monitoring service, patients may need to set up their own protections:
- Place a credit freeze if your letter lists a Social Security or driver’s license number. Freezes at Equifax, Experian and TransUnion are free and can be lifted temporarily when you apply for credit.
- Check the account tied to any financial information in your letter. Review recent statements for unfamiliar charges or withdrawals, since account fraud can surface faster than other identity theft.
- Review Explanation of Benefits statements from your orthopedic visits. Look for surgeries, imaging, braces or therapy sessions you did not receive.
- Consider an IRS Identity Protection PIN. With Social Security numbers and birth dates potentially exposed, a PIN makes it harder for someone else to file a tax return in your name.
- Ignore unexpected requests that mention the cyberattack. Fraudsters often cite real incidents, so check any such message using contact details you look up yourself rather than ones included in the message.
This list is a starting point rather than legal advice. A legal professional can tell you which rights may be available given what your letter says.
Talk to Wilshire Law Firm
Did Casper Orthopedics send you a breach notice?
Did a September letter from Casper Orthopedics say your Social Security number, financial account or medical information may have been exposed? Wilshire Law Firm’s nationally recognized, award-winning team of data privacy lawyers can review what happened, including the timing of the notice and the absence of free monitoring, and explain whether a class action may be an option for affected patients. You can reach a legal professional 24/7 for free consultations and free case reviews, and there are no fees unless you get paid.
Contact Wilshire Law Firm to talk through your Casper Orthopedics notice with our team.
FAQs
The practice says it discovered the attack on or about May 23, 2026. Its investigation concluded on June 11, 2026, and notices went to affected individuals on September 8, 2026.
According to its notice, Casper spent the time after its investigation reviewing the affected information to identify the people involved and their addresses, a process it says was completed on September 2, 2026. The practice also states that its notification was not delayed by a law enforcement investigation.
The notice lists first and last name, date of birth, driver’s license number, Social Security number, financial account information, and medical information, with the exposed elements varying from person to person.
The practice’s report to the U.S. Department of Health and Human Services lists 56,197 affected individuals. Casper has not said how that total divides between patients and others.
Its online notice does not describe any complimentary credit monitoring or identity protection service. If your individual letter includes an offer, follow its enrollment instructions; otherwise, a credit freeze is a free protection you can set up yourself.
Threat-intelligence reporting says the Anubis ransomware group claimed responsibility for an attack on the practice on July 12, 2026, saying patient data and medical records had been exposed. Casper has not attributed the attack to any group, and the claim is unverified.
Possibly. The notice says Social Security numbers, financial account information and medical information may have been exposed, HHS lists more than 56,000 affected individuals, no free monitoring is described in the practice’s notice, and letters went out more than three months after the attack was discovered. Facts like these are often reviewed in class action investigations, though whether you have a claim depends on your own circumstances, which a free case review can help assess.


What Information May Have Been Involved
Social Security, license, bank and medical details
Casper’s notice lists the information potentially exposed as first and last name, date of birth, driver’s license number, Social Security number, financial account information, and medical information. The practice stresses that the affected data differed for each person and that not everyone had every element exposed.
That combination matters. A Social Security number paired with a birth date and driver’s license number can be used to open accounts in someone else’s name, financial account details carry a more immediate risk of unauthorized withdrawals, and medical information can be used to bill for care a patient never received. Casper says it has found no evidence that information in its care has been specifically misused.