Rebound Orthopedics & Neurosurgery, a Vancouver, Washington-based orthopedic and neurosurgery practice, may be facing a new data security incident tied to one of its outside vendors. A cybercriminal group has claimed responsibility for stealing data connected to the practice’s billing operations, raising concerns for patients whose personal and medical information may have been handled by that vendor.
Companies that are entrusted with sensitive patient information, whether directly or through a third-party service provider, have a responsibility to keep that information secure. When a vendor relationship is exploited by hackers, the patients whose data passed through that system can still be left exposed, even though they never dealt directly with the vendor themselves.
Rebound Orthopedics & Neurosurgery’s Data Breach Investigation
According to a posting on a dark web leak site, a cybercriminal group known as Settra claimed responsibility for a cybersecurity incident involving MedEvolve, a healthcare revenue cycle management and billing software company used by Rebound Orthopedics & Neurosurgery. The group reportedly claimed that approximately 820 gigabytes of data were removed from MedEvolve’s systems. As of this writing, neither Rebound Orthopedics & Neurosurgery nor MedEvolve has publicly confirmed the incident, and the specific categories of information involved have not been disclosed.
Vendor-based breaches like this one are an increasingly common way for sensitive healthcare data to be exposed. Medical practices routinely rely on third-party billing, scheduling, and records-management companies to handle day-to-day operations, and each of those vendors represents another potential point of entry for hackers. A single successful attack on a shared vendor can expose data belonging to patients of many different healthcare providers all at once, which is part of why these incidents can affect such a large number of people even when the healthcare provider’s own internal systems were never directly compromised.
Healthcare data is also considered especially valuable on the black market because it often includes a combination of identifying information, such as names, dates of birth, and Social Security numbers, alongside medical and insurance details. That combination can allow criminals to commit various forms of fraud, including opening new financial accounts, filing fraudulent tax returns, or submitting fraudulent insurance claims, sometimes for extended periods of time before the fraud is discovered by the victim.
Rebound Orthopedics & Neurosurgery has previously disclosed at least one earlier, separate data security incident in past years. That prior event is a distinct matter from this new vendor-related claim and is not the subject of this investigation; the two should not be treated as reporting on the same breach. As more facts become available about the scope of the current incident, including whether affected individuals will receive formal notification letters, this page will be updated accordingly.
Regulators in many states require companies to notify affected individuals within a set window once a breach involving personal information has been confirmed, though timelines and specific triggering thresholds vary. Until Rebound Orthopedics & Neurosurgery or MedEvolve issues an official notification, the exact number of people affected and the specific data elements involved remain unconfirmed.
When Did This Breach Occur?
The claimed incident was posted to a dark web leak site in September 2026, with the underlying intrusion estimated by researchers to have occurred in August 2026. Neither Rebound Orthopedics & Neurosurgery nor MedEvolve has issued an official public statement confirming the date of any unauthorized access at this time.
What Information Was Breached?
The specific categories of personal or medical information potentially involved have not yet been confirmed or disclosed publicly. Given that MedEvolve provides billing and revenue cycle services to healthcare practices, the type of information typically handled through such a vendor can include patient names, contact details, insurance information, and billing records, though it has not been confirmed which, if any, of these were affected in this incident.
What You Can Do
If you have received care from Rebound Orthopedics & Neurosurgery, there are steps you can take to help protect yourself while more information becomes available:
- Monitor your financial accounts and insurance statements for any unfamiliar activity
- Consider placing a fraud alert or credit freeze with the major credit bureaus
- Be cautious of unsolicited calls, texts, or emails referencing this incident
- Keep any notification letter you receive, as it may be needed to support a legal claim
- Change passwords on any online accounts tied to your healthcare provider and enable two-factor authentication where available
File a Data Breach Lawsuit Against Rebound Orthopedics & Neurosurgery
If you were a patient of Rebound Orthopedics & Neurosurgery and believe your personal information may have been exposed as a result of this incident, you may have legal options available to you. Companies and their vendors that fail to adequately protect the sensitive information entrusted to them can potentially be held accountable through legal action.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.