Skip to content
Back to Blog
high severity August 22, 2026 · 4 min read

Nebraska Orthopaedic Center breach: names, birth dates and SSNs were copied

If you have an account with Nebraska Orthopaedic Center, here’s what’s now in circulation.

A vendor used by Nebraska Orthopaedic Center has confirmed that an unauthorized person copied some patient records from its systems in December 2025. Official notices dated August 18, 2026 say that information includes full name, date of birth, Social Security number, and medical record number. The clinic’s own systems were not involved, and no filing says how many people were affected.

Nebraska Orthopaedic Center breach: names, birth dates and SSNs were copied

Nebraska Orthopaedic Center, a physician-owned orthopedic clinic, used a vendor named Aesto to migrate and archive patient records. On or about December 18, 2025, Aesto had a network security incident that affected a limited portion of its Amazon cloud systems. On May 26, 2026, Aesto said its investigation found that between about December 2 and December 18, 2025, an unauthorized person copied a limited amount of the clinic’s patient information stored on Aesto’s network.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Notices to patients, written by Aesto on the clinic’s behalf and dated August 18, 2026, were filed with the California and Massachusetts Attorneys General. The clinic’s website also points to that notice, and Aesto lists Nebraska Orthopaedic Center among the organizations affected. The information named in the official notice is full name, medical record number, date of birth, and Social Security number. Aesto says it has no evidence the information has been misused. The clinic’s own systems were not affected. No filing states how many people are involved.

Why “our systems were not affected” is the wrong question

The official notice is written to sound contained. It repeats that only a limited amount of information was copied, that the clinic’s own computers were never touched, and that Aesto has no evidence of misuse. Law-firm pages covering the same event often swing the other way, adding driver’s licenses, bank accounts, and insurance numbers that appear in Aesto notices to other clients, not in this clinic’s filing.

Neither version is the one that matters if you were a patient. The files described here are not your visit notes or imaging. They are the three pieces of information that actually get used to impersonate someone — your legal name, the day you were born, and your Social Security number — plus a medical record number that confirms you were a real patient at this clinic. That combination is enough to attempt a tax return, a new credit account, or a phone call about a bill you do not recognize. It does not matter that the copy happened on a vendor’s servers instead of the clinic’s.

The timeline is also easy to gloss over. The copying took place in December 2025. Aesto confirmed it five months later. Letters are dated August 18, 2026, about eight months after the incident. “No evidence of misuse” is what the vendor says it saw on its own network. It is not a report from the IRS, a credit bureau, or another hospital. Social Security numbers do not expire, and the first clear sign of trouble is often a rejected tax return or a bill for care you never received, not a dramatic alert the week the letter arrives.

What to actually expect

  • The official notice is a letter dated August 18, 2026, sent by Aesto on behalf of Nebraska Orthopaedic Center. That letter is the only direct confirmation that your record was in the copied set. If you moved, it may never reach you. Public filings include no names and no total, so there is no reliable public list to consult either way.
  • If this data is used, it often shows up first as a tax-return problem, a credit inquiry you did not make, or a medical bill or insurance statement for an orthopedic visit that was not yours — not as money missing from a checking account.
  • Unexpected calls or emails that already know you were a Nebraska Orthopaedic patient, or that mention the Aesto incident as a reason to “verify” your Social Security number or pay a bill, are a predictable follow-on. The real notice was a dated letter, not a phone request for your SSN.
  • Class-action ads will keep circulating and may list extra data types from other Aesto clients. They do not change what this clinic’s notice actually named, and they cannot take the copied files back.

What you can and cannot fix

If your name, date of birth, Social Security number, and medical record number were in the Aesto files for this clinic, they cannot be pulled back. Those four items are out. No freeze, no lawsuit, and no cleanup service recalls them.

What still helps, in order:

  • Freeze your credit at Equifax, Experian, and TransUnion. This is the data set used to open new accounts. A freeze is free and blocks that path; you can lift it when you need credit.
  • Get an IRS Identity Protection PIN so a tax return cannot be filed with your Social Security number unless that PIN is on it. That is one of the most common ways this exact mix of data is turned into money, often months later.
  • Read every medical bill and insurance explanation of benefits for visits or procedures you did not have. The medical record number gives a billing thief a real patient handle at an orthopedic practice.
  • Remove your listings from people-search sites. The stolen file is a thin record. Broker sites add former addresses, phone numbers, relatives, and employers. That extra layer is what lets someone pass an identity quiz or write a message that sounds like it knows you. Unlike the Aesto copy, those listings can actually be taken down, which makes the leaked record harder to use against you.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Nebraska Orthopaedic Center is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 22, 2026
Affected Unconfirmed
Data exposed Full namesMedical record numbersDates of birthSocial Security numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email