Nebraska Orthopaedic Center Reports Patient Data Incident in Oregon
Nebraska Orthopaedic Center filed a data breach report with Oregon regulators on August 19, 2026. The incident, which occurred in December 2025, involved the exposure of various personal and medical details. Affected individuals should monitor their accounts and take protective measures.
- State
- Oregon
- Breach date
- December 2, 2025
- Reported
- August 19, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
Nebraska Orthopaedic Center submitted a data breach notification to Oregon authorities on August 19, 2026. This report details a data security incident that was identified on December 2, 2025.
The filing indicates that the breach compromised sensitive patient information. Exposed data categories include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. These details were part of the data held by the center.
Such comprehensive exposure, particularly of Social Security Number and various medical data points, can lead to significant risks for individuals. These risks can include potential medical identity theft, fraudulent insurance claims, or broader identity theft. Affected individuals may face increased vulnerability to scams or unauthorized access to their personal information.
Individuals who receive a breach notification from Nebraska Orthopaedic Center should remain vigilant. It is recommended to carefully review explanation of benefits statements from insurers for unfamiliar services, monitor credit reports for suspicious activity, and consider placing a fraud alert or security freeze on credit files. Reviewing financial statements and other personal accounts for unusual transactions is also a prudent step.
This incident underscores the importance of securing sensitive patient data, as detailed in filings with regulatory bodies. The investigation status is currently described as monitoring by the reporting entity.
Source: Attorney General filing