On May 30, 2024, Restorix Health, Inc., discovered that an unauthorized actor had accessed an employee's email account. This breach potentially compromised sensitive personal information of individuals associated with their healthcare partners.
The intrusion occurred between May 7 and May 29, 2024, and was identified after a thorough investigation involving external cybersecurity experts.
The investigation preliminarily concluded the breach affected 38,553 individuals in the United States.
The severity of this breach is significant due to the nature of the data exposed, which by definition contains protected health information (PHI), due to the disclosure to HHS.
The breach was reported on the Restorix Health website and to the U.S. Department of Health and Human Services on February 14, 2025, as detailed in the HHS breach portal.
In response to this incident, Restorix Health took steps to secure their systems and engaged third-party forensic experts to assist in the investigation. The company has implemented additional cybersecurity safeguards, enhanced employee cybersecurity training, and improved their cybersecurity policies, procedures, and protocols to minimize the likelihood of such incidents in the future.
Restorix Health is notifying affected individuals via mail, starting February 14, 2025. Those who do not receive a letter but wish to know if they are affected can call 1-833-799-4480 for more information. The company encourages individuals to remain vigilant against identity theft and fraud by reviewing account statements and monitoring credit reports. They provide guidance on placing fraud alerts and security freezes on credit files to protect against misuse of personal information.
The following hospitals are considered "Covered Entities" that the data breach notice covers: