logo

Four months after learning of a vendor’s breach, Concord Orthopaedics notifies almost 68,000 patients (1)

ID: 6551adef-b0cf-59f5-8f77-1f82b93d4895

STIX ID: report--6551adef-b0cf-59f5-8f77-1f82b93d4895

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2025-03-27

Date Updated: 2026-05-13

Author: Dissent

...
...

In November 2024 a threat actor group called Everest Team posted a 2.9 GB tranche of data allegedly taken from a vendor that handles Concord Orthopaedics’ patient registration and check-in software. The breached dataset reportedly contains extensive unencrypted PII and PHI—including names, dates of birth, Social Security numbers, driver’s license images, insurance details, and appointment information—affecting tens of thousands of patients (notifications reported 67,835 New Hampshire residents affected and 1,517 Massachusetts residents). Concord Orthopaedics states its internal environment was not impacted and that the vendor provided the potentially impacted data on January 28, 2025; the leak was publicly advertised on a dark web leak site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.