Were you recently affected by a data breach?

Rebound Orthopedics & Neurosurgery Data Breach

A cybercriminal group claims to have stolen data from MedEvolve, the billing vendor used by Rebound Orthopedics & Neurosurgery. Patients may have been affected.

Rebound Orthopedics & Neurosurgery
Date of Breach: Not yet publicly confirmed (dark web claim posted September 2026)
CAU logo

Who was affected:

Clients of Rebound Orthopedics & Neurosurgery

Impacted Data:

Specific data types have not been publicly disclosed at this time

Rebound Orthopedics & Neurosurgery, a Vancouver, Washington-based orthopedic and neurosurgery practice, may be facing a new data security incident tied to one of its outside vendors. A cybercriminal group has claimed responsibility for stealing data connected to the practice’s billing operations, raising concerns for patients whose personal and medical information may have been handled by that vendor.

Companies that are entrusted with sensitive patient information, whether directly or through a third-party service provider, have a responsibility to keep that information secure. When a vendor relationship is exploited by hackers, the patients whose data passed through that system can still be left exposed, even though they never dealt directly with the vendor themselves.

Rebound Orthopedics & Neurosurgery’s Data Breach Investigation

According to a posting on a dark web leak site, a cybercriminal group known as Settra claimed responsibility for a cybersecurity incident involving MedEvolve, a healthcare revenue cycle management and billing software company used by Rebound Orthopedics & Neurosurgery. The group reportedly claimed that approximately 820 gigabytes of data were removed from MedEvolve’s systems. As of this writing, neither Rebound Orthopedics & Neurosurgery nor MedEvolve has publicly confirmed the incident, and the specific categories of information involved have not been disclosed.

Vendor-based breaches like this one are an increasingly common way for sensitive healthcare data to be exposed. Medical practices routinely rely on third-party billing, scheduling, and records-management companies to handle day-to-day operations, and each of those vendors represents another potential point of entry for hackers. A single successful attack on a shared vendor can expose data belonging to patients of many different healthcare providers all at once, which is part of why these incidents can affect such a large number of people even when the healthcare provider’s own internal systems were never directly compromised.

Healthcare data is also considered especially valuable on the black market because it often includes a combination of identifying information, such as names, dates of birth, and Social Security numbers, alongside medical and insurance details. That combination can allow criminals to commit various forms of fraud, including opening new financial accounts, filing fraudulent tax returns, or submitting fraudulent insurance claims, sometimes for extended periods of time before the fraud is discovered by the victim.

Rebound Orthopedics & Neurosurgery has previously disclosed at least one earlier, separate data security incident in past years. That prior event is a distinct matter from this new vendor-related claim and is not the subject of this investigation; the two should not be treated as reporting on the same breach. As more facts become available about the scope of the current incident, including whether affected individuals will receive formal notification letters, this page will be updated accordingly.

Regulators in many states require companies to notify affected individuals within a set window once a breach involving personal information has been confirmed, though timelines and specific triggering thresholds vary. Until Rebound Orthopedics & Neurosurgery or MedEvolve issues an official notification, the exact number of people affected and the specific data elements involved remain unconfirmed.

When Did This Breach Occur?

The claimed incident was posted to a dark web leak site in September 2026, with the underlying intrusion estimated by researchers to have occurred in August 2026. Neither Rebound Orthopedics & Neurosurgery nor MedEvolve has issued an official public statement confirming the date of any unauthorized access at this time.

What Information Was Breached?

The specific categories of personal or medical information potentially involved have not yet been confirmed or disclosed publicly. Given that MedEvolve provides billing and revenue cycle services to healthcare practices, the type of information typically handled through such a vendor can include patient names, contact details, insurance information, and billing records, though it has not been confirmed which, if any, of these were affected in this incident.

What You Can Do

If you have received care from Rebound Orthopedics & Neurosurgery, there are steps you can take to help protect yourself while more information becomes available:

  • Monitor your financial accounts and insurance statements for any unfamiliar activity
  • Consider placing a fraud alert or credit freeze with the major credit bureaus
  • Be cautious of unsolicited calls, texts, or emails referencing this incident
  • Keep any notification letter you receive, as it may be needed to support a legal claim
  • Change passwords on any online accounts tied to your healthcare provider and enable two-factor authentication where available

File a Data Breach Lawsuit Against Rebound Orthopedics & Neurosurgery

If you were a patient of Rebound Orthopedics & Neurosurgery and believe your personal information may have been exposed as a result of this incident, you may have legal options available to you. Companies and their vendors that fail to adequately protect the sensitive information entrusted to them can potentially be held accountable through legal action.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not yet publicly confirmed (dark web claim posted September 2026)
Date of Breach: Reported to the Vermont Attorney General's Office on September 8, 2026
Date of Breach: Not yet publicly confirmed (dark web claim posted September 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.