Desert Orthopaedic Center Data Breach Exposes Social Security Numbers and Medical Records

Published: 7 October 2026
Healthcare data breach illustration
Breach Discovery: August 2026Breach Notification: October 2026

Desert Orthopaedic Center, a Las Vegas orthopedic practice, learned in August 2026 that patient data may have been accessed without authorization. Exposed information may include names, Social Security numbers, medical records, and insurance details. The practice’s review is ongoing and no total affected count has been released. Affected patients should watch for a notice letter and enroll in the free credit monitoring being offered.

CompanyDesert Orthopaedic Center
IndustryHealthcare
Data Types ExposedSocial Security Numbers, Names and Contact Information, Dates of Birth, Treatment and Diagnosis Information, Medication Information, Medical Record Numbers, Medicare and Medicaid ID Numbers, Health Insurance and Billing Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Desert Orthopaedic Center Data Breach?

Desert Orthopaedic Center, an orthopedic medical group serving patients in the Las Vegas area, has disclosed a data privacy incident involving patient information. The practice says certain files may have been accessed or copied by an unauthorized party. This Desert Orthopaedic Center data breach has raised concerns among patients whose sensitive medical and personal details may be at risk.

According to the practice’s own notice, unauthorized access to its network occurred in August 2026. The practice has not said how the access happened or what systems were involved. As a result, the exact method used by the intruder remains undisclosed to the public.

After discovering the issue, Desert Orthopaedic Center brought in outside specialists to investigate. That investigation confirmed that certain files may have been accessed or copied without permission. However, the practice describes its review as ongoing, meaning the full scope of affected individuals and data has not yet been finalized.

The practice issued a formal Notice of Data Event in October 2026, roughly two months after it first learned of the issue. This gap between discovery and public notice is common in healthcare breach cases, since forensic reviews of large patient databases take time. Because the investigation continues, additional details could still emerge as the practice finishes its analysis.

Who was affected?

The breach appears to affect patients of Desert Orthopaedic Center, including individuals whose data was collected for treatment, billing, or insurance purposes. Because orthopedic practices handle both clinical and financial records, the affected group likely spans a wide range of ages and circumstances. Some patients may have only basic contact information exposed, while others could have more sensitive medical details involved.

The practice has not publicly disclosed a total number of affected individuals. Class Action U’s reporting on this incident does not include a specific figure, either. Therefore, this article will not estimate one. Anyone who received care from Desert Orthopaedic Center should consider themselves potentially affected until they receive a notice letter confirming otherwise.

Notice letters will be mailed once the data review is complete, according to the practice. In the meantime, former and current patients in the Las Vegas region should watch their mail closely. Because the review is ongoing, it’s possible more people could be identified as affected in the coming weeks.

What Information Was Potentially Exposed?

The categories of information involved vary from patient to patient. Desert Orthopaedic Center has stated that exposed data may include a combination of identity, contact, medical, and billing details. Not every patient will have had every category exposed, so your individual notice letter is the best source of what applies to you specifically.

  • Full names
  • Contact information
  • Dates of birth
  • Social Security numbers
  • Treatment and diagnosis information
  • Medication information
  • Dates of service
  • Provider names and locations
  • Medical record numbers
  • Patient account numbers
  • Medicare and Medicaid ID numbers
  • Health insurance information
  • Billing and claims information

This combination of data is particularly concerning because it blends identity markers with clinical and financial details. Unlike a stolen credit card number, which can simply be cancelled, a Social Security number paired with medical history cannot easily be replaced. This makes the exposed information valuable to criminals for a longer period of time.

Because insurance identifiers and medical record numbers were included, medical identity theft is a realistic concern. Someone with this information could attempt to obtain treatment, prescriptions, or insurance reimbursements in a patient’s name. In addition, the exposure of Social Security numbers raises the risk of traditional identity theft, including fraudulent credit applications and tax fraud.

What is the company doing?

Desert Orthopaedic Center says it began a response and investigation with third-party specialists after learning of the incident. The practice states it has no reason to believe the exposed information has been or will be misused. Still, out of caution, it is offering complimentary credit monitoring and identity protection services to potentially affected individuals.

The practice has also set up a dedicated assistance line for questions and enrollment in these protective services. Once its data review concludes, Desert Orthopaedic Center plans to mail notice letters to everyone it can identify as potentially affected. Because the investigation is still underway, further updates may follow as more facts become available.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected patients should request copies of their credit reports and review them closely for unfamiliar accounts or inquiries. You can get free reports from all three major bureaus at annualcreditreport.com. Checking regularly helps you catch fraudulent activity early, before it causes lasting financial damage.

In addition to credit reports, review your bank and credit card statements for charges you don’t recognize. Because Social Security numbers were involved, this breach carries a long-term risk that extends well beyond the next few months. Ongoing vigilance, rather than a one-time check, gives you the best protection.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers were among the exposed data, placing a fraud alert or credit freeze is a smart precaution. A fraud alert warns lenders to verify your identity before opening new credit in your name. A credit freeze goes further by blocking access to your credit file entirely until you lift it.

You can contact Equifax, Experian, and TransUnion individually to place these protections, and they are free by law. Because freezing your credit only takes a few minutes per bureau, it’s a relatively low-effort step with meaningful protection. If you ever need to apply for credit, you can temporarily lift the freeze.

Watch for Medical Identity Theft

Because treatment, diagnosis, and insurance information were exposed, patients should also watch for signs of medical identity theft. This can include unfamiliar charges on an explanation of benefits statement or bills for services you never received. Catching these signs early can prevent your medical records from becoming permanently tangled with someone else’s.

If you spot anything suspicious, contact your health insurer immediately to dispute the charges. Keep records of every call and letter in case you need to prove the fraud occurred later. This documentation can also support a legal claim if you decide to pursue one.

Stay Alert for Phishing Attempts

Scammers often use news of a breach to pose as the affected organization, an insurer, or a credit monitoring provider. Because your contact information and provider details may have been exposed, any message referencing your care could look convincing. However, legitimate organizations will not ask for sensitive information through unsolicited texts or emails.

If you receive a suspicious message, don’t click any links or provide information. Instead, contact Desert Orthopaedic Center or your insurer directly using a phone number you already trust. Reporting suspicious contacts to the Federal Trade Commission at identitytheft.gov also helps track broader scam patterns tied to this breach.

Enroll in Free Identity Protection Services

Desert Orthopaedic Center is offering complimentary credit monitoring and identity protection to potentially affected patients. Once you receive your notice letter, enroll as soon as possible, since these offers often come with enrollment deadlines. This service can alert you quickly if someone tries to misuse your information.

Even with monitoring in place, you should still check your own accounts and statements regularly. Monitoring services are a helpful backup, not a replacement for personal vigilance. Together, these steps give you the strongest possible defense against the fallout from this breach.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Browse all recent data breaches →