HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Greater Pittsburgh Orthopedic Associates
bd_89ae0f264e159c03 · schema v1 · pii pii-v1
Full breach record for Greater Pittsburgh Orthopedic Associates →Greater Pittsburgh Orthopedic Associates Inc. reported a data security incident detected on August 10, 2025, involving unauthorized access to its computer network. The breach potentially compromised patients' names, mailing addresses, Social Security numbers, and provider names. The organization engaged third-party forensic experts, secured its environment, notified law enforcement, and offered free credit monitoring services to affected individuals.
Vermont clock✗ VT AG >45 bday28 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by ransomhouse about this victim predates this filing by 647 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_efe761f8ec18ada7Maine State AGfiled 2026-02-20Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-20-greater-pittsburgh-orthopedic-associates-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- 770e3631ae883e23efadb739c80f05746acc89b29c2f84df2555085944ab9b7a
Reporting entity
- Name
- Greater Pittsburgh Orthopedic Associatesnorm: greater pittsburgh orthopedic associates
- Domain
- gpoa.com
Victim entity
- Name
- Greater Pittsburgh Orthopedic Associatesnorm: greater pittsburgh orthopedic associates
- Domain
- gpoa.com
Incident
- Discovered
- Aug 10, 2025
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified law enforcement regarding this incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 weeks(194 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.