Atlanta does not seem to be a safe place for cybersecurity of orthopedic patients’ data. In 2016, orthopedic clinics in Atlanta got clobbered by two big breaches involving thedarkoverlord. The first was a cut and extortion demand on Athens Orthopedic Clinic, an organisation that had more than a dozen locations but somehow didn’t make enough insurance to offer their patients any complimentary citation monitoring services. We also learned about a indorsement cut and extortion effort by thedarkoverlord against Peachtree Orthopedic, who after initially (and falsely) claiming that I had my facts all wrong, finally disclosed their breach, only to have more than 500,000 patients’ data dumped by thedarkoverlord shortly thereafter. Now another chain of Atlanta orthopedic centers has been strike by threat actors. This time, it is Piedmont Orthopedics / OrthoAtlanta that has been hit, and by Pysa (Mespinoza) threat actors. The threat actors get already dumped more than 3.5 gigabit of data. Much of it is information about rentals and business aspects, but looking through the files, i found a number of highly detailed medical records on patients that include their name, date of birth, address and contact information, diagnosis, surgical details, laboratory tests, cardiograms, and indemnity info — pages and pages of protected health information. The files may hold been exfiltrated on July 11, looking at the time-stamps in the dumped archive. There is no notice on the medical group’s website and nothing on HHS’s public transgress tool at this time. DataBreaches.net sought a statement and additional details from the medical group but did not let a reply by publication time. This post will live updated if a reply is received. But Piedmont Orthodpedics/OrthoAtlanta is not the only medical group to have been smasher recently by ransomware. The snapper for fertility and Gynecology in California and Olympia house Rehab, also in California, hold both been recently smash by Netwalker ransomware. Neither i of those latter entities has any observation on their web sites, and the attackers hold not yet dumped any of their data, although they have posted some screenshots as proof of access and are threatening to underprice data soon if their victims don’t pay up. DataBreaches.net also reached out to the Netwalker victims for additional details and any statement, but also received no reply from them by publication time.