No SI-BONE data breach lawsuit has been filed as of mid-2026. At least two law firms — Federman & Sherwood and Maxey Law Firm — have opened investigations into potential class action claims after the medical device company disclosed in October 2025 that an unauthorized party had accessed sensitive personal and health information belonging to hundreds of people.1Federman & Sherwood. SI-BONE Inc Data Breach Investigated by Federman & Sherwood2Maxey Law Firm. SI-BONE Data Breach Lawsuit Investigation
What Was Exposed
SI-BONE reported the breach to the Texas Attorney General on October 1, 2025, disclosing that approximately 955 Texas residents had been affected. The company acknowledged the incident may have reached residents of other states as well, though no broader figure has been made public.3ClaimDepot. SI-BONE 2025 Data Breach
The exposed information covered a wide range of sensitive categories: names, Social Security numbers, dates of birth, addresses, driver’s license or government-issued ID numbers, medical information, health insurance information, and financial information.3ClaimDepot. SI-BONE 2025 Data Breach That combination is unusual and consequential. Identifiers like Social Security and driver’s license numbers are the raw material for identity theft, while medical and insurance data trigger a separate layer of legal protection.
SI-BONE’s public response, based on available records, was limited to issuing state-required disclosures and notifying affected individuals through print media.3ClaimDepot. SI-BONE 2025 Data Breach The date the breach itself occurred, as distinct from when it was reported, has not been disclosed.
Who Is Investigating
Federman & Sherwood announced its investigation on October 2, 2025, saying it was working to determine the scope and consequences of the incident.1Federman & Sherwood. SI-BONE Inc Data Breach Investigated by Federman & Sherwood Maxey Law Firm announced its own investigation and flagged a specific question it wants answered: whether the Social Security numbers involved were encrypted at the time of the breach.2Maxey Law Firm. SI-BONE Data Breach Lawsuit Investigation
Neither firm has filed a complaint. There is no case number, no court, and no lead plaintiff. Both investigations remain open as of mid-2026.
Why the Encryption Question Matters
Encryption can significantly limit the real-world harm from a breach. If Social Security numbers were stored in plain text and taken by an unauthorized party, the risk of identity fraud rises sharply, and so does the strength of any negligence-based claim against the company. If the data was encrypted, the exposure story looks different. SI-BONE has not publicly answered this question, and it is one of the pieces of information the investigating firms are trying to establish.
What SI-BONE Has Said About Legal Exposure
SI-BONE’s annual report for the fiscal year ending December 31, 2024, does not list any pending lawsuits in its legal proceedings section.4SEC. SI-BONE Inc Form 10-K, Fiscal Year Ended December 31, 2024 That filing predates the October 2025 breach disclosure, so it would not capture anything arising from the incident.
The company’s risk factors do, however, anticipate this kind of exposure. The 10-K warns that failures to comply with data privacy and security laws could produce “regulatory investigations or actions; litigation (including class claims) and mass arbitration demands; fines and penalties.”5SI-BONE Inc. SI-BONE Annual Report
What Affected Individuals Can Do
If you received a breach notice from SI-BONE, keep it. It documents that your data was involved, which is typically required to join any class action that later gets filed. The investigating firms are accepting contact from affected individuals during the investigation phase, and being on their intake list is how you learn if and when a complaint is filed.1Federman & Sherwood. SI-BONE Inc Data Breach Investigated by Federman & Sherwood2Maxey Law Firm. SI-BONE Data Breach Lawsuit Investigation
Because Social Security numbers and financial information were exposed, standard identity-theft precautions apply: monitoring credit reports, considering a credit freeze, and watching health insurance statements for unfamiliar charges. Medical identity theft moves differently than financial identity theft and can take longer to surface.