Were you recently affected by a data breach?

Desert Orthopaedic Center Data Breach

Desert Orthopaedic Center, a Las Vegas orthopedic practice, reported a data privacy incident it learned of on or about August 7, 2026. Certain information may have been accessed or copied without authorization, and the review is ongoing.

Desert Orthopaedic Center
Date of Breach: August 7, 2026 (date practice learned of the incident)
CAU logo

Who was affected:

Clients of Desert Orthopaedic Center

Impacted Data:

Names, contact information, dates of birth, Social Security numbers, treatment and diagnosis information, medication information, dates of service, provider names and locations, medical record numbers, patient account numbers, Medicare and Medicaid ID numbers, health insurance information, billing and claims information

Desert Orthopaedic Center, a multispecialty orthopedic practice serving patients in the Las Vegas area, has announced a data privacy incident in which certain patient-related information may have been accessed or copied without authorization. The practice says its review of the scope is still underway.

Medical practices hold some of the most sensitive records there are, from identity details to treatment history, and they carry a responsibility to protect that information. When it may have been exposed, patients deserve clear answers about what happened and what comes next.

Desert Orthopaedic Center’s Data Breach Investigation

Desert Orthopaedic Center, often shortened to DOC, is an orthopedic medical group in the Las Vegas, Nevada area. In a Notice of Data Event dated October 6, 2026, the practice disclosed that it learned of a potential data privacy incident on or about August 7, 2026. After discovering the incident, DOC began a response and investigation with the help of third-party specialists.

That investigation determined that certain DOC information may have been accessed or copied without authorization. The practice describes its review of the scope and impact as ongoing, which means the full list of affected people and the final set of exposed data may not yet be settled. DOC has said it will mail notice letters to potentially affected individuals for whom it has address information once its data review is complete.

The notice does not say how the unauthorized access happened, what systems were involved, or how many people are affected, and the practice has not published a total. This page does not estimate one. Where a fact has not been made public, we say so rather than guess, and the page will be reviewed if the practice or a regulator releases more detail.

The information that may have been involved varies from person to person. The notice says it may include a name together with one or more categories of contact, identity, medical and insurance data, which are described in the section below. Because the exact mix differs for each patient, the notice letter you receive is the best record of what applies to you.

DOC states that it has no reason to believe any information has been or will be misused as a result of the matter. It also says that, out of an abundance of caution, it is offering complimentary credit monitoring and identity protection services at no cost to people who may be impacted, and it has set up a dedicated assistance line for questions and enrollment. A statement that there is no known misuse is not a guarantee, so it is sensible to stay alert regardless.

Healthcare organizations are frequent targets for cyberattacks because patient files combine data that is valuable on its own, such as Social Security numbers and dates of birth, with details that can be used to commit medical identity theft or insurance fraud. A single patient record can hold identity, billing and clinical information in one place, which makes it more useful to a criminal than a stolen payment card number that can simply be cancelled and replaced.

Medical identity theft deserves particular attention. Someone who has a person’s name, insurance identification number and date of birth may try to obtain care, prescriptions or reimbursements in that person’s name, and the first sign can be an unfamiliar item on an explanation of benefits statement or a bill for services never received. Cleaning up a corrupted medical history can take far longer than replacing a card, which is why monitoring early matters.

Exposed contact details can also fuel convincing phishing attempts. After a breach becomes public, scammers sometimes pose as the practice, an insurer or a credit monitoring company and ask for payment or personal information. A message that references a real appointment or provider name may look legitimate even when it is not. Contact the practice or your insurer using a number you already trust rather than one given in an unexpected message.

Patients who were treated at DOC, including those whose information may have been held for billing or insurance purposes, should watch for the notice letter and review it carefully when it arrives. Keep a copy along with any enrollment instructions and deadlines for the free monitoring services. Notices often arrive well after an incident is discovered, so receiving a letter later does not mean the underlying event just happened.

When Did This Breach Occur?

Desert Orthopaedic Center says it learned of a potential data privacy incident on or about August 7, 2026. The practice published its Notice of Data Event on October 6, 2026. The notice does not state when the unauthorized access began or how long it lasted, and the practice’s review is still ongoing.

The practice has said it will send notice letters by mail after it completes its data review. Those letters should give each person the most reliable account of the timeline and of the information involved in their own case.

What Information Was Breached?

The practice says the information potentially involved varies by individual and may include a person’s name and one or more of the following: contact information, date of birth, Social Security number, treatment or diagnosis information, prescription or medication information, dates of service, provider name and location, medical record number, patient account number, Medicare or Medicaid ID number, health insurance information, and medical billing or claims information.

Not everyone will have had every category exposed. Your notice letter should say which items apply to you.

What You Can Do

If you were a patient of Desert Orthopaedic Center or believe you may be affected, consider these steps:

  • Watch for the notice letter and enroll in the complimentary credit monitoring and identity protection services the practice says it is offering.
  • Review your credit reports and account statements for activity you do not recognize, and check explanation of benefits statements for services you did not receive.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Be skeptical of unexpected calls, texts or emails that mention your care or insurance, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Desert Orthopaedic Center

If your information may have been exposed in this incident, you may have legal options. Healthcare providers are expected to safeguard the sensitive information patients entrust to them, and a class action can help hold an organization accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 7, 2026 (date practice learned of the incident)
Date of Breach: Not yet disclosed
Date of Breach: December 30, 2025 to June 7, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.