HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTBIOMETRICMediumActive
Excelsior Orthopaedics, LLC
bd_363c3e7a23ad9f0e · schema v1 · pii pii-v1
Full breach record for Excelsior Orthopaedics, LLC →Excelsior Orthopaedics, LLP, a healthcare provider in Amherst, NY, notified the Maryland AG of a data security incident discovered on June 23, 2024. The breach compromised patient and employee data, including names, SSNs, driver's license numbers, and biometric information. 18 Maryland residents were identified and notified starting December 31, 2024. The organization engaged forensic investigators, reported to the FBI and HHS/OCR, and offered 12 months of credit monitoring.
Leak gap clock✗ Leak >180d17 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by monti about this victim predates this filing by 508 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_72914f9f10127101Vermont State AGfiled 2025-09-02(72d gap)Candidate
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376110.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 34b175cfeb5b6000af2d5f422676921c70a13310dc460fe7a14826f7682bcb33
Reporting entity
- Name
- Wilson, Elser, Moskowitz, Edelman & Dicker LLPnorm: wilson elser moskowitz edelman dicker
Victim entity
- Name
- Excelsior Orthopaedics, LLCnorm: excelsior orthopaedics
- Domain
- excelsiorortho.com
Incident
- Discovered
- Jun 23, 2024
- Materiality determined
- —
- Notification sent
- Jul 25, 2024
- Affected individuals
- 18
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTBIOMETRIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to the U.S. Department of Health and Human Services and the Office for Civil Rights (HHS/OCR)reported this incident to the FBI and cooperated with law enforcement investigations
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 months(508 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.