Bone & Joint Clinic, S.C. Data Breach
Bone & Joint Clinic Network Breach Affects 105,000 Patients
What happened in the Bone & Joint Clinic, S.C. data breach?
The Bone & Joint Clinic, S.C. data breach was reported on March 13, 2023 and affected 105,094 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Bone & Joint Clinic, S.C. Breach Details
Breach Overview
Bone & Joint Clinic, S.C., a Wisconsin-based orthopedic healthcare provider, reported a significant hacking incident affecting its network server infrastructure that compromised the protected health information of 105,094 patients. The breach was submitted to the U.S. Department of Health and Human Services Office for Civil Rights on March 13, 2023, following the discovery of unauthorized access to the clinic's network systems. This incident represents one of the larger healthcare data breaches reported in Wisconsin in recent years, exposing patients to potential identity theft and medical fraud risks. The breach involved unauthorized access to the clinic's network server, where patient records and sensitive medical information were stored electronically.
Company Response and Investigation
Upon discovering the unauthorized network access, Bone & Joint Clinic, S.C. initiated a comprehensive investigation to determine the scope and nature of the security incident. The clinic engaged cybersecurity forensic experts to analyze the breach, identify the vulnerabilities exploited by the attackers, and assess what patient information may have been accessed or exfiltrated during the incident. Following HIPAA breach notification requirements, the clinic submitted its breach report to federal regulators within the required timeframe and began the process of notifying affected patients. The investigation likely involved reviewing server logs, analyzing network traffic patterns, and determining the timeline of unauthorized access to establish which patient records were potentially compromised during the security incident.
Specific Details About the Incident
The breach was classified as a hacking/IT incident affecting the clinic's network server infrastructure, indicating that cybercriminals gained unauthorized access to the organization's computer systems where electronic protected health information (ePHI) was maintained. Network server breaches of this nature typically involve sophisticated attack methods such as exploiting software vulnerabilities, using stolen credentials obtained through phishing campaigns, deploying ransomware or other malware, or leveraging unpatched security weaknesses in the healthcare organization's IT infrastructure. The fact that no business associate was involved suggests that the breach occurred directly within Bone & Joint Clinic's own IT environment rather than through a third-party vendor or service provider. Healthcare organizations increasingly face targeted cyberattacks due to the valuable nature of medical records on the dark web, where complete patient profiles can sell for significantly more than credit card information alone. The breach affected the clinic's network server, which typically serves as the central repository for patient records, scheduling systems, billing information, and clinical documentation.
Organizational Context
Bone & Joint Clinic, S.C. is an orthopedic specialty practice serving patients throughout Wisconsin, providing specialized care for musculoskeletal conditions, injuries, and disorders. As a specialty clinic focused on orthopedic medicine, the organization maintains detailed medical records including diagnostic imaging, surgical histories, treatment plans, and rehabilitation protocols for patients seeking care for bone, joint, and connective tissue conditions. The clinic's patient population likely includes individuals requiring ongoing orthopedic care, surgical interventions, sports medicine services, and pain management treatments. With over 105,000 individuals affected by this breach, the clinic represents a substantial healthcare provider in the Wisconsin market, suggesting multiple locations or a long operational history that has accumulated a significant patient database. Orthopedic practices typically maintain extensive documentation including X-rays, MRI results, surgical notes, physical therapy records, and prescription histories, all of which may have been accessible on the compromised network servers.
Patient Impact and Notifications
The breach affected 105,094 individuals who had entrusted their personal and medical information to Bone & Joint Clinic, S.C. for orthopedic care and treatment. Under HIPAA breach notification rules, healthcare providers must notify affected individuals within 60 days of discovering a breach affecting 500 or more people, and must also report the incident to the Department of Health and Human Services and, in some cases, to prominent media outlets serving the affected area. Patients who received care at Bone & Joint Clinic during the period when their information was stored on the compromised network servers were potentially affected, regardless of whether they were active patients at the time of the breach discovery. The notification letters sent to affected individuals likely included information about what types of data may have been accessed, what steps the clinic was taking to address the security incident, and what resources were being offered to help patients protect themselves from potential identity theft or fraud. Given the March 2023 submission date, patients would have begun receiving notification letters in early to mid-2023, providing them with information needed to take protective measures.
Industry Context and HIPAA Requirements
This breach highlights the ongoing cybersecurity challenges facing healthcare organizations of all sizes, from large hospital systems to specialty clinics. According to the U.S. Department of Health and Human Services, hacking and IT incidents have become the most common type of large healthcare data breach, accounting for the majority of reported incidents in recent years and affecting millions of Americans annually. The healthcare sector remains a prime target for cybercriminals due to the comprehensive nature of medical records, which contain not only personal identifying information but also insurance details, medical histories, and financial data that can be exploited for various fraudulent purposes. HIPAA's Security Rule requires covered entities to implement administrative, physical, and technical safeguards to protect electronic protected health information, including regular risk assessments, employee training, access controls, and encryption where appropriate. When breaches occur, the HIPAA Breach Notification Rule mandates specific timelines and procedures for notifying affected individuals, the Secretary of Health and Human Services, and in some cases the media. Healthcare organizations that experience breaches may face regulatory investigations, potential civil monetary penalties, and requirements to implement corrective action plans to address security deficiencies. The size of this breach—affecting over 100,000 individuals—places it among the more significant healthcare data security incidents reported to federal regulators and underscores the critical importance of strong cybersecurity measures in protecting patient information.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Bone & Joint Clinic, S.C. Breach
Monitor all financial accounts, credit reports, and Explanation of Benefits (EOB) statements from health insurers for unauthorized activity, requesting free credit reports from all three major bureaus (Equifax, Experian, TransUnion) and reviewing them carefully for unfamiliar accounts or inquiries
Consider placing a fraud alert or security freeze on credit files with all three credit bureaus to prevent unauthorized accounts from being opened, which is particularly important if Social Security numbers were compromised in the breach
Review all medical records and insurance statements for unfamiliar services, treatments, or prescriptions that may indicate medical identity theft, contacting healthcare providers and insurers immediately if discrepancies are found
Enroll in any credit monitoring or identity theft protection services offered by Bone & Joint Clinic as a result of the breach, and maintain vigilance for phishing emails or phone calls from individuals claiming to be from the clinic or related to the breach
File taxes early each year to reduce the risk of fraudulent tax returns being filed using stolen Social Security numbers, and consider requesting an Identity Protection PIN from the IRS for additional security
Document all communications related to the breach and any suspicious activity, keeping records of notification letters, monitoring service enrollment, and any fraud incidents that may be connected to the compromised information
Contact Bone & Joint Clinic directly if you have questions about what specific information was compromised in your case or what additional resources may be available to affected patients
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits