NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Casper Orthopedic Associates; Atlantic Digestive Specialists Announce Data Breaches

Data breaches have been announced by Casper Orthopedic Associates in Wyoming and Atlantic Digestive Specialists in New Hampshire.

Casper Orthopedic Associates

Casper Orthopedic Associates, an orthopedic medical practice in Casper, Wyoming, has notified 56,197 individuals about a cybersecurity incident that exposed some of their protected health information. Casper Orthopedic Associates said it discovered it was the victim of a cyberattack on May 23, 2026, and engaged third-party cybersecurity experts to help contain, remediate, and investigate the incident.

The investigation concluded on June 11, 2026, and determined that patient data may have been acquired by an unauthorized third party in the incident. The data review was completed on September 2, 2026, and notification letters were mailed to the affected individuals on September 8, 2026. The impacted data included a combination of names, dates of birth, driver’s license numbers, Social Security numbers, financial account information, and medical information.

Atlantic Digestive Specialists

Atlantic Digestive Specialists, a multi-location gastroenterology practice in New Hampshire, has disclosed a security incident involving unauthorized access to systems containing patient information. Atlantic Digestive Specialists said it was alerted to suspicious network activity in March 2026 and, assisted by third-party cybersecurity experts, determined that an unauthorized third party accessed its network between March 16, 2026, and March 17, 2026, and potentially acquired files containing patient information.

The data review was completed on September 8, 2026, when it was confirmed that the impacted data included names in combination with some or all of the following: date of birth, Social Security number, driver’s license/state identification number, financial account information, payment card information, alien registration number, taxpayer identification number, passport number, clinical information, diagnosis, mental/physical condition, medical history, medical record number, medical treatment information, prescription information, Medicaid/Medicare number, medical cost, dates of service, provider name, patient account number, health insurance information, username/password information, and digital/electronic signature. Notification letters started to be mailed to the affected individuals on September 30, 2026. The number of affected individuals has not yet been publicly disclosed.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist