Four months after learning of a vendor’s breach, Concord Orthopaedics notifies almost 68,000 patients (1)
ID: 6551adef-b0cf-59f5-8f77-1f82b93d4895
STIX ID: report--6551adef-b0cf-59f5-8f77-1f82b93d4895
Feed Name: DataBreaches.Net
In November 2024 a threat actor group called Everest Team posted a 2.9 GB tranche of data allegedly taken from a vendor that handles Concord Orthopaedics’ patient registration and check-in software. The breached dataset reportedly contains extensive unencrypted PII and PHI—including names, dates of birth, Social Security numbers, driver’s license images, insurance details, and appointment information—affecting tens of thousands of patients (notifications reported 67,835 New Hampshire residents affected and 1,517 Massachusetts residents). Concord Orthopaedics states its internal environment was not impacted and that the vendor provided the potentially impacted data on January 28, 2025; the leak was publicly advertised on a dark web leak site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
