CSIDB logo
Incident

Alta Orthopaedics Medical Group

Incident posture

Attack window
Feb 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 17:38

Linked entities

Victim
Alta Orthopaedics Medical Group
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Alta Orthopaedics reported a ransomware attack that exposed the personal and health information of approximately 24,500 individuals. The compromised data included names, contact details, Social Security numbers, driver’s license numbers, passport numbers, financial account information, dates of birth, login information, diagnoses, treatment details, medical record numbers, patient account numbers, service dates, visit reasons, provider names, prescriptions, billing codes, health insurance information, and biometric data. Notification letters were sent to affected individuals, offering complimentary credit monitoring and identity theft protection for 24 months. The INC Ransom group claimed responsibility, stating that 26 gigabytes of data were exfiltrated and later leaked.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 3, 2026, an unauthorized third party gained access to the network of Alta Orthopaedics Medical Group, a specialty medical practice with locations in Santa Barbara, Solvang, Santa Maria, and Oxnard, California, and maintained access until February 6, 2026. Unusual network activity was identified by the organization on March 10, 2026, prompting an internal investigation. The investigation determined that the breach had occurred during the earlier February window and that the review of the affected data was completed on June 24, 2026.

The review concluded that the protected health information of 24,496 individuals was exposed and potentially stolen. Personally identifiable information that may have been compromised included names, contact information, Social Security numbers, driver’s licence numbers or state ID numbers, other government ID numbers, passport numbers, financial account information, dates of birth, and login information. Protected health information that may have been compromised included diagnoses, treatment information, treatment cost information, clinical information, medical record numbers, patient account numbers, dates of service, reasons for visits, provider names, prescription information, billing codes, health insurance information, and biometric data. While the notification letters did not mention ransomware, the article notes that the incident appears to have been a ransomware attack.

Notification letters were mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services were made available for 24 months. The INC Ransom ransomware group claimed responsibility for the attack, stating that 26 GB of data had been exfiltrated and that the data was subsequently leaked. No further details about mitigation or technical remediation were provided in the source material.

Sources

Sources available to members: 1 source.

CSIDB