DataBreachLegalCenter.com
MonitoringOregon AG filing · August 19, 2026

Nebraska Orthopaedic Center Reports 2025 Data Breach to Oregon AG

Nebraska Orthopaedic Center reported a data security incident to the Oregon Attorney General on August 19, 2026, that occurred on December 2, 2025. This breach potentially exposed sensitive patient information, including personal identifiers and detailed medical records. Individuals who received a notification letter should review its contents to understand the specific impact and their next steps.

State
Oregon
Breach date
December 2, 2025
Reported
August 19, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Prescription Information
  • Provider and Treatment Dates

Nebraska Orthopaedic Center, a provider of orthopedic surgery and musculoskeletal care, reported a data security incident to the Oregon Attorney General on August 19, 2026. The breach event itself was identified on December 2, 2025. While the specific type of breach remains unspecified in public records, it involved vulnerabilities within the organization's digital infrastructure or vendor network.

According to the report, the exposed information includes a range of highly sensitive patient data. This compromised data consists of Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates.

The exposure of such a combination of personal and protected health information creates significant and lasting risks for affected individuals. Unlike standard financial breaches where accounts can be closed, medical identity theft can lead to fraudulent insurance claims, inaccurate medical histories, and compromised treatment records. When Social Security Numbers and Dates of Birth are exposed alongside clinical data, the threat of comprehensive identity theft and even tax fraud becomes an enduring concern.

Healthcare providers like Nebraska Orthopaedic Center are obligated by federal and state regulations, including HIPAA, to safeguard patient data with robust security measures. A breach of this nature suggests potential gaps in the administrative, physical, or technical safeguards that are designed to protect electronic protected health information. Such incidents indicate that data may have been left vulnerable to unauthorized access.

If you have received a data breach notification letter from Nebraska Orthopaedic Center, it confirms that your private information was compromised. Understanding this letter is key to recognizing your position and exploring potential avenues for recourse. You are not required to demonstrate financial loss to seek legal advice; the increased risk of future harm is often sufficient ground to evaluate your options.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Oregon Attorney General filing

Related data breach cases