Concord Orthopaedics Data Breach Details
The incident occurred on November 21, 2024, when Concord Orthopaedics was notified that an unauthorized actor may have accessed its third-party software used for patient registration and appointment intake. Upon learning of the breach, Concord Orthopaedics took swift steps to protect its environment. The practice shut down access to the third-party software, reset passwords, and engaged external cybersecurity specialists to assess the scope and nature of the incident.
The investigation revealed that an unauthorized party had accessed the third-party software and potentially viewed or acquired patient registration and appointment intake information. However, no evidence of compromise to Concord’s internal systems or its electronic health records (EHR) system, which is hosted on a separate application, was found.
To support this effort, Concord is offering access to identity protection services. Individuals can sign up for these services to monitor their personal information and mitigate potential risks of identity theft. Detailed information about the identity protection services, including instructions on how to enroll, is provided in the notification letters sent to affected individuals.
What Information Was Compromised?
The information that may have been exposed depends on what was provided during the patient’s registration and appointment intake process. While the specifics vary for each individual, the types of information that could have been affected include:
-
Name
-
Date of Birth
-
Social Security Number
-
Appointment Information: This may include appointment type (e.g., surgical, MRI), the name of the treating physician, and the date and location of the appointment.
-
Health Insurance Information: This includes health plan beneficiary number, health plan number, and insurance eligibility information. Some of this information may belong to the primary insurance holder.
-
Driver’s License or State Identification Number: For some individuals, an image of their driver’s license or state identification card may have been impacted.