Central Texas Pediatric Orthopedics breach affected 140,000 patients

Organization
Central Texas Pediatric Orthopedics
Exploit
Hacking
Industry
Healthcare

Central Texas Pediatric Orthopedics, an Austin practice, reported that an unauthorised party was inside its network between 23 and 26 January 2025. The practice identified suspicious activity on 25 January and confirmed on 4 February that files containing patient information had been accessed, according to HIPAA Journal. Paubox reported the practice dated its awareness of the incident to around 3 March.

The exposed information included patient names, dates of birth, government issued identification numbers such as passport and state identification numbers, medical information including X-ray images, and health insurance details.

The Qilin ransomware group claimed the attack and listed the practice on its dark web leak site, where reports said at least 42 gigabytes of stolen material was offered in February. Neither the practice nor the group disclosed whether a ransom was demanded or paid.

The reported scale grew over time. A notice filed with the Texas Attorney General on 6 March 2025 covered about 90,000 Texas residents. A subsequent report to the US Department of Health and Human Services Office for Civil Rights on 4 April 2025 put the total at 140,000 individuals.

The practice said it worked with outside forensic specialists, deployed additional endpoint detection and response software, and offered affected patients complimentary credit monitoring and identity theft protection. Several plaintiffs' firms announced investigations in the weeks that followed.

Sources