Data Breach & Privacy
Blog > Data Breach & Privacy
Comprehensive Orthopaedics Data Breach: February Discovery, August Notice
Comprehensive Orthopaedics, a Connecticut orthopedic practice, says an unauthorized party accessed files on its network that may have held Social Security numbers, card details and medical information. Its federal breach report counts 21,897 people. Here’s the timeline and what patients can do.

What Happened at Comprehensive Orthopaedics
Suspicious network activity found on February 12, 2026
Comprehensive Orthopedics & Musculoskeletal Care, LLC, the Connecticut practice that patients know as Comprehensive Orthopaedics, says it became aware of suspicious activity on its network on February 12, 2026. Its website notice, dated August 14, 2026, says the practice secured the environment, hired an outside forensic firm, and learned that certain files had been accessed by an unauthorized third party.
Threat-intelligence firm SOCRadar lists a claim against the practice by a ransomware group called Crypto24, first recorded on March 9, 2026. That listing reflects the group’s own assertion. The practice’s notice does not name any group or explain how the intruder got in.
What Information May Have Been Involved
Identity, financial and health details in the files
According to the notice, the affected files may have contained a person’s first and last name along with one or more of the following: date of birth, Social Security number, government-issued ID, financial account or payment card information, medical information and health insurance information. Which items apply differs from person to person.
Because the list spans financial, identity and health information, the risks run in several directions: card and account numbers can be used for direct charges, Social Security and ID numbers for opening new accounts, and insurance details for false medical claims. The notice does not say whether any misuse has been detected.
Who the Comprehensive Orthopaedics Breach Affects
More than 21,000 individuals listed by HHS
Comprehensive Orthopaedics sees patients at offices in Wallingford, Meriden, Southington and Cheshire, Connecticut. Its website describes services ranging from joint replacement and sports medicine to physical therapy, MRI imaging and a walk-in orthopedic urgent care clinic.
The practice reported the breach to the U.S. Department of Health and Human Services on September 10, 2026, as a hacking incident involving a network server, and the federal listing shows 21,897 affected individuals. The notice does not say how many of them are patients. Searches of the breach lists kept by the California, Vermont and Texas attorneys general, and of Massachusetts’ 2026 breach report, turned up no filing for this incident as of October 2, 2026.
How Comprehensive Orthopaedics Responded
Passwords reset, accounts secured, letters mailed
The practice says it secured its network, reset passwords, secured all accounts and completed a full investigation. It is also mailing notice letters to people whose information may have been involved, although the notice does not give a mailing date.
Its website notice does not mention free credit monitoring or identity protection. The timeline is long: about four months passed between the February discovery and the end of the file review on June 17, 2026, and roughly two more months went by before the August 14 notice.
Steps You Can Take to Protect Yourself
Steps when card, ID and medical data may be involved
Because the notice lists payment card and account information alongside identity and health details, these steps cover each risk:
- Look over recent card and bank statements first. Unfamiliar charges are the most immediate warning sign when account or card numbers may be exposed.
- Freeze your credit at Equifax, Experian and TransUnion. With Social Security numbers and government IDs possibly involved, a free freeze makes new-account fraud harder.
- Check Explanation of Benefits notices from your health plan. Surgeries, therapy visits or imaging billed to your plan that you never received can signal medical identity theft.
- Keep the letter when it arrives. It should list which data elements applied to you, which matters if you later explore your options.
- Don’t act on messages that cite the breach. If someone calls, texts or emails about the incident, look up a trusted contact yourself before responding.
None of this is legal advice; a legal professional can tell you which of these steps matter most for you.
Talk to Wilshire Law Firm
Did a Comprehensive Orthopaedics letter reach you?
Did a letter from Comprehensive Orthopedics & Musculoskeletal Care tell you that your Social Security number, card information or medical details may have been in the affected files? Wilshire Law Firm’s nationally recognized, award-winning team handles data breach and privacy claims, and incidents involving this much sensitive information are often reviewed as possible class actions. A legal professional can look at your letter in a free consultation or free case review, our team is available 24/7, and there are no fees unless you get paid.
Get in touch with Wilshire Law Firm today, and we’ll walk through your letter with you.
FAQs
The practice says it became aware of suspicious network activity on February 12, 2026. Its review of the affected files ended on June 17, 2026, its website notice is dated August 14, 2026, and it reported the breach to federal regulators on September 10.
The U.S. Department of Health and Human Services breach listing shows 21,897 affected individuals. The practice has not broken that number down between patients and others.
The notice says the files may have included names together with dates of birth, Social Security numbers, government-issued IDs, financial account or payment card information, medical information and health insurance information. The elements vary by person.
SOCRadar, a threat-intelligence firm, lists a claim by a group called Crypto24 that it first recorded on March 9, 2026. The practice has not named any group, and the claim has not been independently confirmed.
The website notice is silent on monitoring and identity protection. Check your mailed letter for any offer, and remember that a credit freeze costs nothing at the three national bureaus.
According to the notice, the practice spent the months after the February discovery reviewing the affected files to see whose information they held, and that review ended on June 17, 2026. The notice does not explain the roughly two months between the end of the review and the August 14 notice.
You may have options. The practice’s notice lists Social Security numbers, payment card data and medical information among the possibly exposed details, HHS lists 21,897 affected individuals, and about six months passed between discovery and public notice. Breaches with those facts are often evaluated for class action claims, and a free case review can show whether one may apply to you.

