360 Physical Therapy, LLC Data Breach
360 Physical Therapy Data Theft: 520 Patients Affected
What happened in the 360 Physical Therapy, LLC data breach?
The 360 Physical Therapy, LLC data breach was reported on December 21, 2023 and affected 520 individuals. The breach type was Theft involving Paper/Films. This breach occurred in North Dakota. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
360 Physical Therapy, LLC Breach Details
360 Physical Therapy, LLC Data Breach Report
Incident Overview
360 Physical Therapy, LLC, a physical therapy provider based in North Dakota, experienced a data breach involving the theft of paper records and films on an unspecified date prior to the December 21, 2023 submission to the HHS Office for Civil Rights. The breach resulted in the unauthorized access to protected health information (PHI) belonging to approximately 520 patients. The theft of physical documents—including patient medical records and diagnostic films—represents a significant breach of patient privacy and HIPAA security requirements, which mandate appropriate safeguards for all forms of PHI, whether electronic or paper-based.
Discovery and Response Timeline
The specific date of discovery and the timeline of 360 Physical Therapy's response are not detailed in the available breach notification data. However, the entity's submission to the HHS Office for Civil Rights on December 21, 2023, indicates that the breach was identified, investigated, and reported within the required timeframe mandated by HIPAA's Breach Notification Rule. Under HIPAA regulations, covered entities and business associates must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The involvement of a business associate in this incident suggests that 360 Physical Therapy may have engaged a third-party vendor for records management, storage, or other administrative functions, which would have required contractual safeguards and breach notification protocols.
Breach Mechanism and Operational Impact
The breach involved the theft of paper records and films, which are physical forms of PHI commonly found in healthcare settings. Physical document theft represents a vulnerability that many healthcare organizations continue to face despite the industry's shift toward electronic health records (EHR). Paper-based records and diagnostic films (such as X-rays, MRI films, or ultrasound images) are particularly vulnerable to theft because they require physical storage in secure locations, proper access controls, and regular inventory management. The theft likely occurred from a facility location such as a records room, storage area, or administrative office where patient files are maintained. This breach type underscores the importance of implementing comprehensive physical security measures, including locked storage cabinets, restricted access areas, surveillance systems, and regular audits of document inventory.
Organizational Context
360 Physical Therapy, LLC operates as a physical therapy provider in North Dakota, offering rehabilitation and therapeutic services to patients recovering from injuries, surgeries, or chronic conditions. Physical therapy clinics typically maintain extensive patient records containing detailed medical histories, treatment plans, progress notes, and diagnostic imaging. The organization's size, based on the 520 affected individuals, suggests a regional practice or a single facility with a moderate patient population. North Dakota-based healthcare providers serve a geographically dispersed population across a rural state, which may present unique challenges for records management and physical security. The involvement of a business associate indicates that 360 Physical Therapy outsourced certain functions—potentially including records storage, billing, or administrative services—to a third-party vendor, which is common among smaller healthcare organizations seeking to reduce operational overhead.
Patient Impact and Notification
Approximately 520 patients of 360 Physical Therapy had their protected health information compromised in this theft. These individuals received breach notification letters informing them of the incident, the types of information exposed, and recommended protective measures. The notification process, required under HIPAA's Breach Notification Rule, must include a description of the breach, the types of information involved, steps patients should take to protect themselves, and information about the entity's response to the breach. Patients affected by this incident were likely notified by mail or other means of contact on file with the organization. The 60-day notification window from discovery to patient notification is a critical requirement designed to give patients timely information so they can take protective action against potential identity theft or fraud.
Data Exposure and HIPAA Implications
The theft of paper records and diagnostic films from a physical therapy provider likely exposed multiple categories of sensitive PHI. Physical therapy records typically contain patient names, dates of birth, addresses, telephone numbers, insurance information, medical histories, diagnoses, treatment plans, and clinical notes. Diagnostic films may include identifying information embedded in the image itself or on the film jacket. Depending on the organization's record-keeping practices, Social Security numbers, financial account information, or emergency contact details may also have been included in the stolen documents. Under HIPAA's Security Rule, covered entities must implement administrative, physical, and technical safeguards to protect all forms of PHI. The theft of paper records represents a failure in physical safeguards, which require healthcare organizations to implement facility access controls, workstation security, and protection of physical media. This breach demonstrates the ongoing vulnerability of paper-based records in healthcare settings and the necessity for organizations to conduct regular risk assessments and implement appropriate controls proportionate to the sensitivity of the information stored.
Industry Context and Similar Incidents
Theft of paper records and physical media remains a persistent vulnerability in healthcare despite the industry's transition to electronic systems. According to HHS breach notification data, theft incidents account for a significant portion of healthcare data breaches, particularly in smaller healthcare organizations and specialty practices. Physical therapy clinics, dental offices, and other outpatient providers frequently maintain paper records due to regulatory requirements, patient preference, or operational inertia. The involvement of a business associate in this breach highlights the importance of vendor management and contractual safeguards. HIPAA requires covered entities to ensure that business associates implement appropriate safeguards through Business Associate Agreements (BAAs) that specify security requirements and breach notification obligations. Similar incidents involving theft of paper records from healthcare facilities have resulted in regulatory action, financial penalties, and mandatory implementation of enhanced security measures. The HHS Office for Civil Rights has emphasized that healthcare organizations must treat paper records with the same level of protection as electronic data, including encryption, access controls, and secure disposal procedures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the 360 Physical Therapy, LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review medical records and explanation of benefits (EOB) statements from your health insurance provider for unauthorized services, claims, or charges. Contact your insurance company and healthcare providers immediately if you identify suspicious activity.
Monitor financial accounts, including bank accounts and credit cards, for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
Consider enrolling in identity theft protection or credit monitoring services, which may be offered by 360 Physical Therapy or available through your insurance provider. These services can provide early warning of fraudulent activity.
If you believe you are a victim of identity theft or fraud, file a report with the Federal Trade Commission (FTC) at IdentityTheft.gov and contact local law enforcement. Obtain a copy of the FTC Identity Theft Report to provide to creditors and financial institutions.
Request a copy of your medical records from 360 Physical Therapy to verify accuracy and ensure no unauthorized services have been documented under your name.
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies, as criminals may use stolen information to conduct targeted phishing or social engineering attacks.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More North Dakota Breaches
Search all breaches reported in North Dakota