Skip to main content

Morning Overview

Casper Orthopedic Associates reported a breach affecting 56,197 people

Casper Orthopedic Associates, an independent orthopedic group in Casper, Wyoming, has told federal regulators that a cyberattack exposed the records of 56,197 people. The data that may have been taken includes Social Security numbers, driver’s license numbers, financial account information and medical information, though the practice says the mix differed from patient to patient.

The dates show how slowly a breach of this kind can surface. The practice found the attack around May 23, 2026, and the count reached HHS on July 23, but patient letters did not go out until September 8, and the story reached trade and tracker sites in early October.

The timeline from May discovery to September mailing

According to the practice’s own incident notice, an unauthorized third party attacked its systems and Casper discovered it on or about May 23. Its investigation, run with outside cybersecurity experts, concluded on June 11 and found that sensitive information “may have been acquired” from the practice’s systems. A separate review to identify who was affected, and where to mail them, finished on September 2.

Notifications went to people believed to be affected on September 8. The practice states that it notified law enforcement and that the notification was not delayed by any law enforcement investigation. The notice does not describe how the attacker got in, and neither does the practice name a group or claim of responsibility.

Casper says it has since added security safeguards, improved physical security at the practice, and continues to strengthen its cybersecurity policies, procedures and protocols. Those are the only remediation steps the notice names. It does not say whether systems were encrypted, whether patient care was interrupted, or whether the practice paid anyone, details that would normally help patients judge how seriously to treat the possibility of misuse.

The 56,197 count and the HHS filing

Both ClaimDepot’s breach page and Becker’s Spine Review put the figure at 56,197 and say the breach was logged with the HHS Office for Civil Rights on July 23. Becker’s reported the story on October 2; ClaimDepot published on October 1 and updated its page on October 6. ClaimDepot’s list of disclosure sources also names a dozen state attorneys general, from California and Texas to Vermont and Washington, along with Massachusetts regulators, which suggests patients in many states were among those written to.

Reporting to HHS is a legal duty. Under the HIPAA Breach Notification Rule, a breach affecting 500 or more people must be reported to the HHS Secretary within 60 days of discovery, and individuals must be told in writing without unreasonable delay and no later than 60 days. Measured against the rule, the gap between the June 11 finding and the September 8 mailing is explained by the practice as the time needed to identify who was affected and their addresses.

Casper describes itself as an independent practice in a single Wyoming city, which makes the number notable: 56,197 people is a large patient file for one orthopedic group, and ClaimDepot’s list of a dozen state regulators shows it reaches well beyond Wyoming. The notice and the trackers do not break the total down by state, and the Wyoming figure, if any, has not been published in the material available.

Exposed data and the protections the notice offers

The categories listed in the notice are first and last names, dates of birth, Social Security numbers, driver’s license numbers, financial account information and medical information. Casper says it has found no evidence the information has been specifically misused. That is a statement about what the practice has detected so far, and the notice itself describes the information as possibly acquired, not confirmed stolen.

One unusual detail is what the notice leaves out. Neither the practice’s page nor ClaimDepot’s summary mentions free identity-protection services for patients. Instead, the notice points people to the Federal Trade Commission’s identity-theft guidance and to the three credit bureaus, Equifax, Experian and TransUnion, and says to report suspected fraud to police and the state attorney general. Questions go to an incident line at 1-877-344-1660, open Monday to Friday from 8 a.m. to 8 p.m. Eastern.

The FTC’s consumer page on credit freezes and fraud alerts explains the two tools the notice leans on. A freeze is free, blocks new credit accounts in a person’s name until lifted, and is placed with all three bureaus. A fraud alert is also free but only requires lenders to verify identity first; an initial alert lasts one year and is placed with one bureau, which must tell the other two. With a Social Security number and a driver’s license number in play, a freeze is the stronger of the two for a patient who received a Casper letter.

Still missing from the record is the cause. Casper has said an unauthorized party reached its systems, and none of the published accounts say how, who, or whether any data has surfaced for sale.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.