Notice of Data Privacy Incident

Precision Orthopedics & Sports Medicine is committed to protecting the privacy and security of the information in our care. On February 13, 2025, we began mailing notification letters to certain patients whose information was involved in an incident.

We recently completed an investigation related to a phishing email incident. On September 12, 2024, we learned of unusual activity in our email system. We immediately began an investigation and worked with third-party experts to contain and remediate the issue. The investigation determined that between September 10, 2024 and September 12, 2024, an unauthorized party had accessed some employee email accounts as a result of a phishing email.

On January 2, 2025, we determined that the accessed emails contained information that varied per patient but included patient names and one or more of the following: patients’ dates of birth, services received, dates of service, treating provider, medication information, and treatment and/or diagnostic information. The accessed emails did NOT contain patients’ Social Security numbers or financial information.

It is always a good idea for patients to remain vigilant and review statements received from their healthcare provider. If patients identify charges for services they did not receive, they should contact the healthcare provider immediately.

We take this matter very seriously. In order to help prevent a similar incident, we will continue to implement and evaluate enhanced safeguards and security measures to further protect our email system, and continue to provide training to our employees regarding phishing emails.

We have set up a designated incident response line to answer patient questions. Patients can call 1-833-903-3648, Monday through Friday from 9 am – 9 pm Eastern Time, except for major U.S. holidays. We remain committed to protecting the confidentiality and security of the information in our care and apologize for any concern or inconvenience this may cause