Casper Orthopedic Associates, a Wyoming orthopedic practice, discovered a cyberattack in May 2026 that may have exposed names, dates of birth, driver’s license numbers, Social Security numbers, financial account information, and medical information for 56,197 patients. Notification letters went out in September 2026. Affected individuals should monitor credit reports and consider a credit freeze immediately.
| Company | Casper Orthopedic Associates |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Names, Dates of Birth, Driver’s License Numbers, Social Security Numbers, Financial Account Information, Medical Information |
| People Affected | 56,197 individuals |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Casper Orthopedic Associates Data Breach?
Casper Orthopedic Associates, an orthopedic medical practice based in Casper, Wyoming, has confirmed a significant data breach affecting tens of thousands of patients. The practice discovered unauthorized access to its network in May 2026. As a result, sensitive patient data may have fallen into the hands of a cybercriminal.
According to the practice, the attacker gained access to its systems before the intrusion was detected. Once the breach was found, Casper Orthopedic Associates brought in outside cybersecurity specialists. These experts worked to contain the threat, remove the attacker’s access, and figure out exactly what happened.
The forensic investigation wrapped up in June 2026. Investigators determined that patient data may have been acquired by an unauthorized third party during the incident. Because medical record reviews can be complex, the practice then spent several more months reviewing exactly which files and individuals were affected.
That review process concluded in September 2026. Casper Orthopedic Associates finished identifying the specific data elements involved and began notifying affected patients directly by mail that same month. This timeline reflects how thoroughly healthcare providers must verify exposed data before alerting patients, even though it can mean a long wait between discovery and notification.
Who was affected?
The breach affects patients of Casper Orthopedic Associates. In total, the practice has notified 56,197 individuals that their protected health information was involved in this incident.
Because this is an orthopedic medical practice, the affected population likely includes patients of varying ages, from younger sports injury patients to older individuals treated for joint and bone conditions. Patients who sought care at this Wyoming-based practice should assume they could be included in the notification group, even if they have not yet received a letter.
It is not yet clear whether minors are among those affected. However, pediatric orthopedic cases are common in this type of practice, so families should remain alert for notification letters addressed to dependents as well.
What Information Was Potentially Exposed?
The data exposed in this breach is especially sensitive because it combines identity documents with financial and medical details. This combination raises the stakes considerably compared to breaches involving only one data category.
- Full names
- Dates of birth
- Driver’s license numbers
- Social Security numbers
- Financial account information
- Medical information
With this type of data in hand, criminals can attempt a wide range of fraud. For example, a stolen Social Security number combined with a date of birth is often enough to open new credit accounts in a victim’s name. Driver’s license numbers add another layer of risk, since they can be used to create fake identification documents.
Medical information exposure carries its own distinct dangers. Criminals sometimes use stolen medical details to commit healthcare fraud, such as submitting fraudulent insurance claims or obtaining prescription medications under someone else’s identity. This can leave victims with incorrect medical records that are difficult and time-consuming to correct.
What is the company doing?
Once Casper Orthopedic Associates discovered the attack, it moved to contain the incident and engaged third-party cybersecurity experts. These specialists helped the practice investigate the scope of the breach and determine what patient data was affected.
After completing its data review in September 2026, the practice began mailing notification letters to all 56,197 affected individuals. This notification effort gives patients the chance to take protective steps, such as monitoring their accounts and placing fraud alerts, before any misuse of their information occurs.
The practice has not publicly disclosed additional details beyond the scope of its investigation and notification process. Patients who received a letter should review it carefully, since it may include specific instructions or offers related to their individual case.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected patients should request copies of their credit reports and review them closely for unfamiliar accounts or inquiries. You can get free reports from all three major credit bureaus through AnnualCreditReport.com.
Because Social Security numbers were exposed, criminals could attempt to open new lines of credit using stolen identities. Regularly checking your reports helps you catch fraudulent activity early, before it causes lasting financial damage.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers, driver’s license numbers, and financial account details were all exposed, affected individuals should strongly consider placing a fraud alert or a full credit freeze on their credit files. A credit freeze restricts access to your credit report, which makes it much harder for criminals to open new accounts in your name.
To set up a freeze, you must contact each of the three major credit bureaus separately. While this takes some effort, it provides one of the strongest protections available against identity theft following a breach like this one.
Watch for Medical Identity Theft
Because medical information was exposed, affected patients should also review any insurance statements or explanation-of-benefits notices they receive. Unexpected charges or unfamiliar treatments listed on these documents could signal medical identity theft.
If you notice anything suspicious, contact your health insurer immediately. In addition, consider requesting a copy of your medical records from Casper Orthopedic Associates to confirm their accuracy.
Stay Alert for Phishing Attempts
Criminals often use stolen personal information to craft convincing phishing emails, texts, or phone calls. Because this breach included names, dates of birth, and other personal details, scammers may try to impersonate Casper Orthopedic Associates or related healthcare providers.
As a result, never click links or share personal information in response to unexpected messages. Instead, verify any communication by contacting the organization directly through a known, official phone number or website.
Consult a Data Breach Attorney
If you received a notification letter, you may want to speak with an attorney who focuses on data breach cases. Many offer free consultations and can help you understand your legal options.
Because this breach involved highly sensitive data, including Social Security numbers and medical records, affected individuals may be eligible for compensation. An attorney can evaluate your specific situation and explain what steps might be available to you.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
