Greater Pittsburgh Orthopaedic Associates (GPOA) reported an August 2025 security incident involving unauthorized access to its IT network, which it detected around August 10, 2025. GPOA told state regulators and affected individuals that a forensic investigation determined patient data could have been compromised, with potentially exposed elements including name, mailing address, Social Security number, and provider name; the organization said it engaged incident response support, notified law enforcement, and began security hardening and awareness efforts.
Regulatory reporting and victim notification timelines and counts appear inconsistent across disclosures: GPOA reported the incident to HHS in late August 2025 as affecting roughly 35,000 individuals, while later filings to the Maine Attorney General indicated 56,954 impacted people, and individual notification letters were mailed in early February 2026. Separately, the RansomHouse leak site listed GPOA in August 2025 and claimed the victim was encrypted, posting a limited “proof pack,” but the listing was not updated and there was no clear confirmation from GPOA that ransomware encryption or data publication occurred.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
In a February 20, 2026 disclosure to the Maine Attorney General, GPOA's external counsel reported that 56,954 people were affected. This updated count was significantly higher than the earlier HHS filing.
On February 5, 2026, GPOA began sending notification letters to affected people about the August 2025 breach. The letters said exposed data may have included names, mailing addresses, Social Security numbers, and provider names, and offered credit monitoring through Cyberscout.
GPOA reported the incident to the U.S. Department of Health and Human Services on August 27, 2025. That filing said the breach affected 35,000 patients.
On August 20, 2025, the RansomHouse ransomware group listed GPOA on its dark web leak site and claimed the organization had been encrypted. The listing included a "proof pack," but was not later updated.
Greater Pittsburgh Orthopaedic Associates said it detected unauthorized access to its IT network on or around August 10, 2025. The organization initiated incident response, engaged third-party experts, and began a forensic investigation.
In May 2024, a group calling itself DonutLeaks allegedly claimed to have hacked "Pittsburgh’s Trusted Orthopaedic Surgeons," which may have referred to GPOA. The incident was not reflected in HHS's public breach tool and remains unconfirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.