Central Texas Pediatric Orthopedics
ent_bcf3f1d483905b62a2a8cbdf
Disclosures
7
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
140,121
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Central Texas Pediatric Orthopedics
- Normalized
- central texas pediatric orthopedics— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Maine State AGas victim2025-04-14
Central Texas Pediatric Orthopedics (CTPO) disclosed a security incident occurring Jan 23-26, 2025, where an unauthorized actor accessed systems containing patient and volunteer data. CTPO discovered the breach on Feb 4, 2025, and notified affected individuals on Apr 11, 2025. Approximately 140,121 individuals were affected, including 9 Maine residents. Data involved names, DOBs, and x-rays. CTPO engaged forensic investigators, notified the FBI, and implemented security enhancements.
- Massachusetts State AGas victim2025-04-14
Central Texas Pediatric Orthopedics reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-14. 50 Massachusetts residents were affected.
- Indiana State AGas victim2025-04-11
Central Texas Pediatric Orthopedics reported a data breach to the Indiana Attorney General. The breach occurred on 2025-01-23 and was reported on 2025-04-11. 32 Indiana residents were affected. 140,121 individuals affected in total.
- Nebraska State AGas victim2025-04-11
Central Texas Pediatric Orthopedics (CTPO) notified Nebraska AG of a security incident occurring Jan 23-26, 2025, where an unauthorized actor accessed systems. CTPO discovered the breach on Feb 4, 2025, identifying access to patient records including minors' names, DOBs, and X-rays. CTPO engaged a forensic firm, reported to the FBI, and implemented security enhancements (EDR, password resets, server rebuilds). Notices were sent April 11, 2025, to affected individuals across multiple states.
- Vermont State AGas victim2025-04-11
Central Texas Pediatric Orthopedics notified patients of a security incident where an unauthorized actor accessed systems from Jan 23-26, 2025. Affected data included minors' names, dates of birth, and x-ray images. The company engaged forensic investigators, notified the FBI, and implemented security enhancements including EDR and password resets.
- TEXASHHS OCRas victim2025-04-04
Central Texas Pediatric Orthopedics (TX) reported to HHS OCR on 2025-04-04 a ransomware attack affecting 140,000 individuals. PHI located on a Network Server was compromised, including names, dates of birth, x-ray images, and other treatment information. The entity is a pediatric orthopedics provider, so affected records likely involve minors. The CE notified HHS, affected individuals, and the media, posted substitute notice, and responded by revising security policies and implementing new technical safeguards.
- Illinois State AGas victim2025-04-01
CENTRAL TEXAS PEDIATRIC ORTHOPEDICS filed a data-breach notice with the Illinois Attorney General in April 2025 (case 25-04-096). The register records the breach as discovered on January 25, 2025. Personal information types reported: biometric data, drivers license, medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.