Classaction Data Breaches at Alta Orthopaedics and Elara Caring Prompt Class Action Investigations
Article Content
- •Alta Orthopaedics experienced a data breach affecting patient information from February 3 to 6, 2026.
- •Elara Caring's breach involved unauthorized access to a third-party vendor's systems, impacting over 60,000 patients.
- •Both organizations are facing potential class action lawsuits as attorneys seek affected individuals.
Alta Orthopaedics disclosed a data breach involving unauthorized access to its network, affecting patient data between February 3 and 6, 2026. The breach was detected on March 10, 2026, and may involve sensitive information such as Social Security numbers and medical records. Elara Caring reported a data breach linked to a third-party vendor, with unauthorized access occurring between November 4-6 and November 14-17, 2025. This breach, affecting over 60,000 patients, was confirmed by a notification letter received from the vendor on December 12, 2025. Both organizations are currently under investigation for potential class action lawsuits, with attorneys seeking affected individuals to come forward. The scope of the breaches raises concerns about patient privacy and data security practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Alta Orthopaedics in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…