A Wyoming orthopedic practice is telling 56,197 patients that their protected health information may have been taken in a spring cyberattack. The attack came to light on May 23, 2026, and Casper Orthopedic Associates then called in outside cybersecurity specialists to contain and investigate the intrusion.
That investigation wrapped up on June 11, 2026, and its finding was that an unauthorized third party may have obtained patient data. Notification letters reached affected individuals on September 8, 2026, after the practice finished reviewing the files on September 2.
The records at risk brought together medical information and financial account information, plus names, birth dates, driver’s license numbers, and Social Security numbers.
Separately, Atlantic Digestive Specialists, a multi-site gastroenterology practice in New Hampshire, said an intruder reached its systems between March 16 and March 17, 2026 and may have lifted files holding patient information. Its review finished on September 8, and the practice said exposed details included names alongside items such as birth dates, Social Security numbers, state IDs, financial and payment card data, passport numbers, clinical information, diagnoses, medical history, and record numbers. Letters began mailing on September 30, and the practice has not yet disclosed how many people were affected.
Why it matters for healthcare security teams — the Casper timeline shows how long disclosure can drag. More than three months passed between discovering the intrusion and mailing patient letters, a stretch in which identity-theft exposure goes unanswered. Practice leaders should build review capacity before an incident, so notification does not stall behind forensic and file-review queues.