OrthoConnecticut
ent_67add6148c0dcd8f1e901ca0
Disclosures
8
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
178,742
nationwide · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- OrthoConnecticut
- Normalized
- orthoconnecticut— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- myorthoct.com
Disclosure history (8)newest first
- Illinois State AGas victim2024-07-01
ORTHOCONNECTICUT PLLC filed a data-breach notice with the Illinois Attorney General in July 2024 (case 24-07-038). The register records the breach as discovered on November 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Vermont State AGas victim2024-07-01
OrthoConnecticut notified consumers of a cybersecurity incident where unauthorized actors accessed its network between Nov 24-28, 2023. The breach potentially exposed names and protected health information. The company contained the threat, engaged forensic investigators, and alerted law enforcement. Notification was sent in July 2024.
- Illinois State AGas victim2024-07-01
ORTHOCONNECTICUT PLLC filed a data-breach notice with the Illinois Attorney General in July 2024 (case 24-07-001). The register records the breach as discovered on November 24, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2024-07-01
OrthoConnecticut experienced unauthorized network access between Nov 24-28, 2023. The incident was discovered on May 10, 2024, after forensic review confirmed personal information (names) may have been accessed. The company contained the threat, engaged third-party forensic investigators, and notified law enforcement. Credit monitoring services are offered to affected individuals.
- New Hampshire State AGas victim2024-04-29
OrthoConnecticut PLLC notified the New Hampshire Attorney General of unauthorized network access between Nov 24-28, 2023. The breach affected personal information of 46 NH residents, including SSNs and names. Discovered March 27, 2024. Notifications sent April 26, 2024, offering credit monitoring.
- CONNECTICUTHHS OCRas victim2024-04-26
OrthoConnecticut PLLC reported to HHS on 2024-04-26 a Hacking/IT Incident affecting 178,742 individuals. Breached information located on Network Server. The incident involved ransomware encrypting PHI including names, SSNs, addresses, DOBs, diagnoses, and treatment info. Response included credit monitoring and security safeguards.
- Vermont State AGas victim2024-04-26
OrthoConnecticut notified Vermont AG of a cybersecurity incident where unauthorized access occurred between Nov 24-28, 2023. The actor accessed and removed files containing patient names and medical information (PHI). Discovery was made on March 27, 2024. The company engaged forensic investigators, secured the network, and offered credit monitoring. No specific count of affected individuals was provided in the filing.
- Massachusetts State AGas victim2024-04-26
OrthoConnecticut PLLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-04-26. 371 Massachusetts residents were affected.