Alliance Physical Therapy Group, LLC Data Breach
Alliance Physical Therapy Group Network Server Breach Affects 197,588
What happened in the Alliance Physical Therapy Group, LLC data breach?
The Alliance Physical Therapy Group, LLC data breach was reported on February 23, 2022 and affected 197,588 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Michigan. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Alliance Physical Therapy Group, LLC Breach Details
Alliance Physical Therapy Group Network Server Breach
Opening Summary
Alliance Physical Therapy Group, LLC, a Michigan-based physical therapy provider, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on February 23, 2022, affecting 197,588 individuals. The incident involved a hacking or IT-related intrusion into the organization's network systems, resulting in potential exposure of protected health information (PHI) and personal data maintained on networked servers. This breach represents a substantial security incident affecting nearly 200,000 patients and individuals who received services or had records maintained by the organization.
Discovery and Response Timeline
The specific discovery date and investigation timeline were not detailed in the breach submission, though the HHS notification was filed on February 23, 2022. Organizations typically discover network-based breaches through several mechanisms: automated security monitoring systems detecting unusual network activity, third-party security researchers reporting vulnerabilities, law enforcement notifications, or evidence of unauthorized data access. Upon discovery of a network server compromise, Alliance Physical Therapy Group would have been required under HIPAA Breach Notification Rule to conduct a thorough investigation to determine the scope of the breach, identify which individuals were affected, and assess what categories of information were exposed. The organization was obligated to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach, as well as notify the HHS Office for Civil Rights and potentially media outlets depending on the number of affected residents in their state.
Technical Details of the Breach
Network server breaches typically occur through several common attack vectors. Hackers may exploit unpatched software vulnerabilities, use compromised credentials to gain unauthorized access, deploy malware or ransomware to infiltrate systems, or conduct social engineering attacks targeting employees with access to critical systems. The fact that this breach involved a network server—rather than a portable device or paper records—suggests the attackers gained access to centralized data repositories where patient records, billing information, and administrative data are typically stored. Network server compromises are particularly concerning because they can potentially expose large volumes of data simultaneously and may go undetected for extended periods if security monitoring is inadequate. The breach likely involved either direct unauthorized access to the server infrastructure or lateral movement through the network after initial compromise of a less-protected system. Given the scale of affected individuals (197,588), the breach appears to have compromised a significant portion of the organization's patient database or multiple interconnected systems.
Organizational Context
Alliance Physical Therapy Group, LLC operates as a physical therapy provider in Michigan, offering rehabilitation and therapeutic services to patients recovering from injuries, surgeries, or managing chronic conditions. Physical therapy clinics and rehabilitation centers maintain extensive patient records including medical histories, treatment plans, diagnostic imaging results, insurance information, and personal identifiers. As a healthcare provider, Alliance Physical Therapy Group is a HIPAA-covered entity responsible for implementing administrative, physical, and technical safeguards to protect patient information. The organization's operations span multiple locations or a significant patient population across Michigan, as evidenced by the nearly 200,000 individuals affected by this breach. The involvement of a business associate in this breach indicates that the organization may have contracted with third-party vendors for services such as billing, IT support, data hosting, or other healthcare operations, and the breach may have originated from or involved systems maintained by these business associates.
Patient Impact and Affected Population
Approximately 197,588 individuals were affected by this breach, representing a substantial portion of Alliance Physical Therapy Group's patient population and potentially including current patients, former patients, and individuals whose information was maintained in the organization's systems. The affected population likely includes patients who received physical therapy services at any of the organization's Michigan locations during the period when their information was stored on the compromised network server. These individuals may have had various categories of personal and health information exposed, depending on what data was maintained in the breached systems. Notification of affected individuals would have been conducted through multiple channels, potentially including direct mail, email, phone calls, or posted notices, with the organization providing information about the breach, the types of data exposed, steps being taken to secure systems, and recommended actions for affected individuals to protect themselves from potential misuse of their information.
HIPAA Compliance and Industry Context
Under the HIPAA Security Rule, covered entities like Alliance Physical Therapy Group are required to implement comprehensive security measures including access controls, encryption, audit controls, and integrity controls to protect electronic protected health information (ePHI). Network server breaches represent a failure in one or more of these required safeguards. The Breach Notification Rule mandates that covered entities notify affected individuals, the HHS Office for Civil Rights, and potentially the media when a breach of unsecured PHI affects more than 500 residents of a state or jurisdiction. Network-based breaches affecting large patient populations have become increasingly common in healthcare, with attackers targeting healthcare providers due to the high value of medical records on the dark web and the critical nature of healthcare operations that may make organizations more likely to pay ransoms. The involvement of a business associate in this breach highlights the importance of vendor risk management and the requirement that covered entities ensure business associates maintain equivalent security standards through Business Associate Agreements (BAAs) and regular oversight.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Alliance Physical Therapy Group, LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized services, and contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Monitor financial accounts and bank statements for unauthorized transactions; consider placing alerts with your financial institutions and reviewing account activity regularly
Consider enrolling in credit monitoring and identity theft protection services if offered by the breached organization; maintain copies of all correspondence related to the breach for your records
Be cautious of unsolicited phone calls, emails, or mail requesting personal or medical information; verify the identity of callers before providing any information
Change passwords for any online accounts associated with the breached organization or your healthcare providers, using strong, unique passwords
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and consider filing a police report for documentation purposes
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Michigan Breaches
Search all breaches reported in Michigan
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits