Close Menu
Creative Learning GuildCreative Learning Guild
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Creative Learning GuildCreative Learning Guild
    Subscribe
    • Home
    • All
    • News
    • Trending
    • Celebrities
    • Privacy Policy
    • About
    • Contact Us
    • Terms Of Service
    Creative Learning GuildCreative Learning Guild
    Home » The $2.4M Excelsior Orthopaedics Data Breach Compromise: A Warning to the Medical Industry
    News

    The $2.4M Excelsior Orthopaedics Data Breach Compromise: A Warning to the Medical Industry

    Errica JensenBy Errica JensenApril 11, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    On the morning of June 23, 2024, Excelsior Orthopaedics’ IT staff discovered a problem with their network somewhere in Western New York. The term “unusual activity” has become a somber euphemism in 2024 for what is nearly always an ongoing ransomware attack. They hired an outside cybersecurity company. They looked into it. Approximately 389,000 people, both current and former patients, had their most private information entrusted to strangers when the extent of what had transpired became apparent. Their records were sitting quietly in databases they had no reason to think about.

    The attack has been attributed to the ransomware group MONTI. Security researchers have been following MONTI since at least 2022. They are a particularly effective group that is prepared to make stolen data public if ransom demands are not fulfilled. MONTI is exposed to more than just names and email addresses when it enters a healthcare network. This type of information, which includes diagnoses, prescription records, biometric data, Social Security numbers, passport numbers, financial account details, and health insurance policy information, is shared by patients with their doctors under the presumption that it will never leave the building. In this instance, all of it might be reachable. Patients who trusted Excelsior Orthopaedics with that information learned about it gradually; some received breach notices in August 2024, others didn’t until December, and still others didn’t find out about the Buffalo Surgery Center connection until a notice appeared on the organization’s website on January 3, 2025. It’s worth putting up with the six-month wait between breach discovery and some notifications.


    CategoryDetails
    Case NameSzucs, et al. v. Excelsior Orthopaedics, LLP, et al.
    Case Number812753/2024
    DefendantsExcelsior Orthopaedics, LLP & Buffalo Surgery Center, LLC
    LocationBuffalo / Western New York, USA
    Breach Discovery DateJune 23–24, 2024
    Initial DisclosureAugust 2024
    Buffalo Surgery Center NoticeJanuary 3, 2025
    Lawsuit FiledFebruary 10, 2026
    Settlement Amount$2,400,000
    Preliminary ApprovalFebruary 10, 2026
    Individuals AffectedApproximately 389,000 current and former patients
    Responsible Threat ActorMONTI ransomware group (claimed responsibility)
    Data CompromisedNames, SSNs, dates of birth, driver’s licenses, passport numbers, biometric data, medical records, diagnoses, health insurance info, financial information, prescription info
    Max Individual PayoutUp to $5,000 (documented losses)
    No-Proof PaymentPro-rated cash amount (no documentation required)
    Free Credit Monitoring2 years, three-bureau (automatic, no claim required)
    Claim DeadlineJune 11, 2026
    Final Approval HearingJuly 8, 2026
    Settlement WebsiteExcelsiorDataSettlement.com
    Laws CitedHIPAA; New York General Business Law; FTC Act
    The $2.4M Excelsior Orthopaedics Data Breach Compromise: A Warning to the Medical Industry
    The $2.4M Excelsior Orthopaedics Data Breach Compromise: A Warning to the Medical Industry

    A $2.4 million class action settlement between Excelsior Orthopaedics and the Buffalo Surgery Center, both located in Western New York, was preliminary approved in February 2026. All current U.S. citizens whose data may have been compromised in the hack—roughly 389,000 people—are covered by the settlement. Following final approval, each class member is automatically eligible for two years of three-bureau credit monitoring and identity theft insurance, which will take effect without the need to file a claim. The settlement offers up to $5,000 in reimbursement for individuals who had documented financial losses, such as bank fees, credit monitoring expenses, time spent handling fraudulent charges, or the cost of replacing a driver’s license or government ID, as long as appropriate documentation is provided. After all other distributions have been made, those without documentation may apply for a prorated cash payment from whatever is left in the fund. The deadline for submitting claims is June 11, 2026.

    The particular list of data that was exposed in this breach is telling. There is a certain intimacy in the records of orthopedic practices. When a patient comes in for a procedure that typically costs tens of thousands of dollars, such as a knee replacement or a torn rotator cuff, they share diagnosis codes, surgical history, prescription details, insurance coverage, and frequently financial information linked to payment plans. That is not the same as your credit card number being lost by a retailer, which is a terrible situation in and of itself. A ransomware group appears to have broken into a single network containing identity documents, medical histories, and physical conditions without setting off an automated alarm. The settlement documents don’t fully address concerns regarding Excelsior’s security posture prior to June 2024 because the breach was found by employees who noticed “unusual activity” rather than by automated defense systems.

    Over the past few years, ransomware attacks have most likely targeted the healthcare sector. There is no mystery to the reasons. More personally identifiable information about each patient can be found in medical records than in nearly any other type of data. The infrastructure used by healthcare organizations is often outdated. Despite having equally sensitive data, small and mid-sized practices, such as orthopedic groups, surgery centers, and specialty clinics, frequently lack the cybersecurity budgets of large hospital systems. Experts have been outlining a pattern in conference rooms and congressional hearings for years, and the Excelsior breach, which affected a regional orthopedic practice and its affiliated surgery center in Buffalo, fits that pattern. There has been no slowdown in the pattern. It has, if anything, accelerated.

    The Excelsior settlement’s future demands on the company are often overlooked in favor of the monetary amount. Excelsior has committed to implementing security improvements to better safeguard patient data as part of the agreement. It remains to be seen if those improvements are broad commitments that meet a settlement requirement without significantly altering the underlying infrastructure, or if they are specific, auditable, and truly consequential. Technical requirements are rarely specified in great detail in settlements of this kind because civil litigation isn’t really meant to produce that kind of outcome. It does, however, result in financial accountability after the fact, which in this instance amounts to about $6.15 per potentially impacted patient. This figure captures the legal resolution but says very little about the true cost of having your passport information, Social Security number, and medical records in the wrong hands.

    Watching these cases go through the system—breach, investigation, lawsuit, settlement, credit monitoring, repeat—makes it difficult not to feel quietly frustrated. The deadline for filing a claim is June 11, 2026. The practical route is simple for former Excelsior Orthopaedics and Buffalo Surgery Center patients who received a notice letter: go to ExcelsiorDataSettlement.com, use the ID and PIN from the notice, and file before the deadline. The more difficult question is why there isn’t a settlement website for an industry that handles some of the most private human data in the world.


    Disclaimer

    Nothing published on Creative Learning Guild — including news articles, legal news, lawsuit summaries, settlement guides, legal analysis, financial commentary, expert opinion, educational content, or any other material — constitutes legal advice, financial advice, investment advice, or professional counsel of any kind. All content on this website is provided strictly for informational, educational, and news reporting purposes only. Consult your legal or financial advisor before taking any step.

    Excelsior Orthopaedics Data Breach Compromise
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Errica Jensen
    • Website

    Errica Jensen is the Senior Editor at Creative Learning Guild, where she leads editorial coverage of legal news, landmark lawsuits, class action settlements, and consumer rights developments and News across the United Kingdom, United States and beyond. With a career spanning over a decade at the intersection of legal journalism, lawsuits, settlements and educational publishing, Errica brings both rigorous research discipline, in-depth knowledge, experience and an accessible editorial voice to subjects that most readers find interesting and helpful.

    Related Posts

    The Bristol Backlash: City Council Under Fire for Replacing Artists with AI

    April 29, 2026

    Harvard’s Architectural Shift: Designing Spaces That Foster Spontaneous Creative Collaboration

    April 29, 2026

    How Ruth E. Carter’s Design Philosophy Is Reshaping What We Teach Young Creatives

    April 29, 2026
    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    News

    The Bristol Backlash: City Council Under Fire for Replacing Artists with AI

    By Errica JensenApril 29, 20260

    72,000 pamphlets were distributed to homes, community centers, and organizations throughout Bristol in July 2025.…

    Harvard’s Architectural Shift: Designing Spaces That Foster Spontaneous Creative Collaboration

    April 29, 2026

    How Ruth E. Carter’s Design Philosophy Is Reshaping What We Teach Young Creatives

    April 29, 2026

    Harvard’s Student Voice: What Undergrads Want Faculty to Know About Using AI

    April 29, 2026

    The Wales Creative Learning Programme Producing the UK’s Most Globally Competitive Young Designers

    April 29, 2026

    The Montclair State Experiment That Could Change How Every College Teaches Creative Thinking

    April 29, 2026

    The STEM-Arts Divide Is Over: Inside the Schools That Are Finally Teaching Both

    April 29, 2026

    The Algorithm Will See You Now: AI’s Role in Diagnosing and Aiding Learning Disabilities

    April 29, 2026

    The AI That Creates Art With Children — and Why Researchers Are Terrified by What It’s Doing to Their Imaginations

    April 29, 2026

    Inside the Shrewsbury Hive: Britain’s Quietest Creative Learning Revolution

    April 29, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Privacy Policy
    • About
    • Contact Us
    • Terms Of Service
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.