Nebraska Orthopaedic Center breach: names, birth dates and SSNs were copied
If you have an account with Nebraska Orthopaedic Center, here’s what’s now in circulation.
A vendor used by Nebraska Orthopaedic Center has confirmed that an unauthorized person copied some patient records from its systems in December 2025. Official notices dated August 18, 2026 say that information includes full name, date of birth, Social Security number, and medical record number. The clinic’s own systems were not involved, and no filing says how many people were affected.
Nebraska Orthopaedic Center customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Nebraska Orthopaedic Center, a physician-owned orthopedic clinic, used a vendor named Aesto to migrate and archive patient records. On or about December 18, 2025, Aesto had a network security incident that affected a limited portion of its Amazon cloud systems. On May 26, 2026, Aesto said its investigation found that between about December 2 and December 18, 2025, an unauthorized person copied a limited amount of the clinic’s patient information stored on Aesto’s network.
Notices to patients, written by Aesto on the clinic’s behalf and dated August 18, 2026, were filed with the California and Massachusetts Attorneys General. The clinic’s website also points to that notice, and Aesto lists Nebraska Orthopaedic Center among the organizations affected. The information named in the official notice is full name, medical record number, date of birth, and Social Security number. Aesto says it has no evidence the information has been misused. The clinic’s own systems were not affected. No filing states how many people are involved.
Why “our systems were not affected” is the wrong question
The official notice is written to sound contained. It repeats that only a limited amount of information was copied, that the clinic’s own computers were never touched, and that Aesto has no evidence of misuse. Law-firm pages covering the same event often swing the other way, adding driver’s licenses, bank accounts, and insurance numbers that appear in Aesto notices to other clients, not in this clinic’s filing.
Neither version is the one that matters if you were a patient. The files described here are not your visit notes or imaging. They are the three pieces of information that actually get used to impersonate someone — your legal name, the day you were born, and your Social Security number — plus a medical record number that confirms you were a real patient at this clinic. That combination is enough to attempt a tax return, a new credit account, or a phone call about a bill you do not recognize. It does not matter that the copy happened on a vendor’s servers instead of the clinic’s.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The timeline is also easy to gloss over. The copying took place in December 2025. Aesto confirmed it five months later. Letters are dated August 18, 2026, about eight months after the incident. “No evidence of misuse” is what the vendor says it saw on its own network. It is not a report from the IRS, a credit bureau, or another hospital. Social Security numbers do not expire, and the first clear sign of trouble is often a rejected tax return or a bill for care you never received, not a dramatic alert the week the letter arrives.
What to actually expect
- The official notice is a letter dated August 18, 2026, sent by Aesto on behalf of Nebraska Orthopaedic Center. That letter is the only direct confirmation that your record was in the copied set. If you moved, it may never reach you. Public filings include no names and no total, so there is no reliable public list to consult either way.
- If this data is used, it often shows up first as a tax-return problem, a credit inquiry you did not make, or a medical bill or insurance statement for an orthopedic visit that was not yours — not as money missing from a checking account.
- Unexpected calls or emails that already know you were a Nebraska Orthopaedic patient, or that mention the Aesto incident as a reason to “verify” your Social Security number or pay a bill, are a predictable follow-on. The real notice was a dated letter, not a phone request for your SSN.
- Class-action ads will keep circulating and may list extra data types from other Aesto clients. They do not change what this clinic’s notice actually named, and they cannot take the copied files back.
What you can and cannot fix
If your name, date of birth, Social Security number, and medical record number were in the Aesto files for this clinic, they cannot be pulled back. Those four items are out. No freeze, no lawsuit, and no cleanup service recalls them.
What still helps, in order:
- Freeze your credit at Equifax, Experian, and TransUnion. This is the data set used to open new accounts. A freeze is free and blocks that path; you can lift it when you need credit.
- Get an IRS Identity Protection PIN so a tax return cannot be filed with your Social Security number unless that PIN is on it. That is one of the most common ways this exact mix of data is turned into money, often months later.
- Read every medical bill and insurance explanation of benefits for visits or procedures you did not have. The medical record number gives a billing thief a real patient handle at an orthopedic practice.
- Remove your listings from people-search sites. The stolen file is a thin record. Broker sites add former addresses, phone numbers, relatives, and employers. That extra layer is what lets someone pass an identity quiz or write a message that sounds like it knows you. Unlike the Aesto copy, those listings can actually be taken down, which makes the leaked record harder to use against you.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
ManageMyHealth 120K Medical Records — December 2025
Medical-records platform ManageMyHealth disclosed a breach affecting ~120,000 patients in December 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…