The Foot and Ankle Wellness Center of Western Pennsylvania confirmed a data breach affecting 653 patients after unauthorized access to its electronic medical records and network server. Exposed data may include patient names and medical record details. Affected individuals should monitor credit reports, watch for phishing attempts, and consider consulting a data breach attorney.
| Company | The Foot and Ankle Wellness Center of Western Pennsylvania |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names, Medical Record Details, Treatment and Diagnosis Information, Electronic Health Record Data |
| People Affected | 653 individuals |
| Attack Method | Unauthorized Access/Disclosure |
| Regulators Notified | California Attorney General, HHS Office for Civil Rights |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Foot and Ankle Wellness Center Data Breach?
The Foot and Ankle Wellness Center of Western Pennsylvania recently confirmed a data breach involving patient information. The practice reported that an unauthorized party accessed its systems, exposing sensitive records without permission.
According to the notification filed with regulators, the breach was classified as unauthorized access or disclosure. As a result, patient files stored on the practice’s electronic medical record system and its network server were involved. The exact discovery date has not been publicly disclosed.
The practice notified the HHS Office for Civil Rights in August 2026. Because healthcare providers must report breaches affecting patient data, this filing set the formal disclosure process in motion. Following the discovery, the center likely worked with forensic specialists to determine the scope of the intrusion and confirm which records were affected.
At this stage, the practice has not released further public detail about how the attacker gained access. However, the classification of the incident as unauthorized access suggests that someone outside normal channels viewed or obtained protected health information without consent.
Who was affected?
The breach affected patients of The Foot and Ankle Wellness Center of Western Pennsylvania. Based on the filing, 653 individuals had their information involved in this incident.
Because this is a specialty medical practice, most affected individuals are likely current or former patients who received podiatric or related care. In addition, it is possible that some records belonged to minors or elderly patients, given the nature of foot and ankle treatment across all age groups.
The practice has not indicated that employees or other non-patient groups were involved. Still, anyone who received care or had records maintained by this provider should consider themselves potentially affected until they receive official confirmation.
What Information Was Potentially Exposed?
The notification specifies that the breach involved data held in an electronic medical record system and a network server. This means the exposed information likely includes clinical and administrative details tied to patient care.
- Patient names
- Medical record details
- Treatment and diagnosis information
- Other data typically stored in electronic health records
Because medical records often include identifying and clinical details together, this type of exposure carries real risk. For example, exposed health information can be used to commit medical identity theft, where a criminal uses a patient’s identity to obtain treatment or prescriptions fraudulently.
In addition, exposed personal details can fuel targeted phishing attempts. Scammers often use real patient information to make fraudulent emails or calls appear legitimate, which increases the chance that a victim will hand over more sensitive data, like insurance or payment information.
What is the company doing?
In response to the breach, the practice filed formal notification with the HHS Office for Civil Rights. This step is required under federal law whenever protected health information is compromised.
The center also filed notice with the California Attorney General, in addition to its filing with the HHS Office for Civil Rights. These filings indicate the practice is treating the incident seriously and following required reporting steps across jurisdictions.
Beyond regulatory filings, healthcare providers in this situation typically strengthen network security and review internal access controls. Although the practice has not detailed every remediation step publicly, patients affected by the breach should expect to receive a direct notification letter explaining the scope of the exposure and any protective resources being offered.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should check their credit reports regularly for unfamiliar accounts or inquiries. This is one of the simplest ways to catch identity theft early.
You can request a free credit report from each of the three major bureaus once a year. Because medical identity theft can sometimes show up as unexpected collections or new accounts, reviewing these reports closely over the coming months is important.
Watch for Phishing Attempts
Because your name and medical details may have been exposed, scammers could try to use this information to appear credible. Be cautious of unexpected calls, emails, or texts claiming to be from a healthcare provider or insurer.
Never click on links or share personal details in response to unsolicited messages. Instead, contact the organization directly using a verified phone number if you’re unsure whether a message is legitimate.
Review Medical Bills and Insurance Statements
Since medical record data was involved, it’s wise to closely review any insurance statements or medical bills you receive. Unexpected charges could be a sign that someone used your information to obtain treatment.
If you notice anything unfamiliar, contact your insurance provider immediately. Reporting suspicious activity quickly can limit further misuse of your medical identity.
Consider a Fraud Alert or Credit Freeze
If you’re concerned about broader identity theft risks, placing a fraud alert or credit freeze on your credit file adds an extra layer of protection. This makes it harder for anyone to open new credit accounts in your name.
A fraud alert is free and lasts one year, while a credit freeze offers more complete protection until you choose to lift it. Because both options are simple to set up, they’re worth considering if you were notified about this breach.
Consult a Data Breach Attorney
If you received a notification letter about this breach, you may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation.
Many attorneys offer free consultations for cases like this. As a result, reaching out costs nothing and can help clarify your legal options moving forward.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
View the public data breach notification listing from HHS Office for Civil Rights
