Pacific Rehabilitation Centers Data Breach Exposes PHI & PII

Published
March 3, 2025
Updated
March 3, 2025
Pacific Rehabilitation Centers Data Breach Exposes PHI & PII
Pacific Rehabilitation Centers
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

On December 30, 2024, Pacific Rehabilitation Centers experienced a significant data breach. An employee discovered a ransomware notice on their computer, prompting immediate action from the company's IT staff.

They swiftly took the servers offline to protect the stored data. While the forensic investigation is still ongoing, it has been confirmed that data on the servers was encrypted. However, it remains unclear if any unauthorized access or exportation of data occurred.

The breach affected approximately 18,900 individuals in the United States.

The compromised information includes a wide range of sensitive data. Personally identifiable information includes names, addresses, social security numbers, dates of brith, and government ID numbers. Protected health information exposed includes information such as diagnosis ande treatment information.

Pacific Rehabilitation Centers's Response

In response to the breach, Pacific Rehabilitation Centers took their servers offline for forensic analysis and transitioned to secure alternative systems within 24 hours to ensure uninterrupted patient care. They have implemented enhanced security measures across all company devices. The executive team is actively working with forensic IT personnel and is leading the transition to an upgraded electronic health record system.

For those potentially affected by the breach, the company recommends placing a free fraud alert on your credit file.

You can contact any of the three major credit bureaus to do so:

Additionally, you can request a free credit report from each bureau to check for unauthorized accounts or inquiries. Report any suspicious activity to the FTC at IdentityTheft.gov.

For further questions, Pacific Rehabilitation Centers has set up an Incident Hotline at 206-635-4401, available from 9 am to 1 pm, Pacific Time. They will provide follow-up notices if new relevant information is obtained.

For more information about the data breach, visit their Notice of Data Security Incident.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • names
  • addresses
  • diagnosis and treatment information
  • social security numbers
  • health plan numbers
  • banking information for direct deposit
  • dates of birth
  • e-mail addresses
  • driver's license numbers
  • citizenship status
  • passport

Join the

Pacific Rehabilitation Centers

data breach lawsuit. It's free to join. 

Join the Lawsuit
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image