
Alta Orthopaedics, a California specialty medical practice with offices in Santa Barbara, Solvang, Santa Maria, and Oxnard has confirmed that a cybersecurity incident earlier this year exposed the protected health information of 24,496 patients.
The practice detected unusual network activity on March 10, 2026, and a subsequent investigation determined that an unauthorized party had accessed its systems between February 3 and February 6, 2026. The review of affected files concluded on June 24, 2026, months after the intrusion itself.
The scope of exposed data is broad ,and may include names, Social Security numbers, driver's license and state ID numbers, passport numbers, financial account details, dates of birth, and login credentials.
On the medical side, exposed records included diagnoses, treatment histories, billing codes, prescription information, health insurance details, and biometric data.
Few breaches touch this many categories of sensitive information at once, which is part of why the incident carries such weight for the patients involved.
Alta Orthopaedics has begun mailing notification letters and is offering 24 months of credit monitoring and identity theft protection to those affected. Notably absent from those letters is any mention of ransomware, though the INC Ransom group has since claimed responsibility for the attack, stating that 26 gigabytes of data were taken and later published online.
Under California law, healthcare providers carry a legal duty to safeguard patient records and to notify individuals promptly once a breach is discovered. When Social Security numbers, government identification, and detailed medical histories end up in criminal hands, the risk to patients extends well past a single stolen password. Identity theft, fraudulent medical claims, and long-term credit damage are all realistic consequences, and the law recognizes that these harms deserve a remedy.
Patients who received a notice from Alta Orthopaedics should act now rather than wait to see if problems surface. Reviewing account statements, freezing credit with the major bureaus, and speaking with an attorney about legal options are all reasonable next steps.
The data privacy and breach lawyers at The Lyon Firm represents individuals harmed by healthcare data breaches across California and is currently reviewing this matter for affected patients seeking accountability and compensation.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: