Coppola Physical Therapy and Fitness Gyms Data Breach
Coppola Physical Therapy Email Breach Affects 632 Patients
What happened in the Coppola Physical Therapy and Fitness Gyms data breach?
The Coppola Physical Therapy and Fitness Gyms data breach was reported on January 31, 2024 and affected 632 individuals. The breach type was Unauthorized Access/Disclosure involving Email. This breach occurred in New Hampshire. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Coppola Physical Therapy and Fitness Gyms Breach Details
Coppola Physical Therapy and Fitness Gyms Data Breach Report
Incident Overview
Coppola Physical Therapy and Fitness Gyms, a healthcare provider operating in New Hampshire, experienced an unauthorized access incident involving its email systems. The breach was reported to the New Hampshire Attorney General on January 31, 2024, affecting 632 individuals. The unauthorized access to email accounts represents a significant compromise of the organization's primary communication infrastructure, which typically contains sensitive patient health information, appointment details, and personal identifiers. This type of breach is particularly concerning because email systems often serve as repositories for protected health information (PHI) that may not be encrypted or subject to the same access controls as dedicated medical record systems.
Discovery and Response Timeline
While specific details regarding the discovery date are not provided in the breach submission, the January 31, 2024 submission date indicates that Coppola Physical Therapy initiated the notification process within the required HIPAA timeframe. Upon discovering the unauthorized access, the organization undertook an investigation to determine the scope of the breach, identify which email accounts were compromised, and assess what patient information may have been accessed or disclosed. The involvement of a business associate in this incident suggests that the breach may have involved third-party vendors or service providers who handle patient data on behalf of the primary healthcare entity. This complicates the breach response, as multiple organizations must coordinate notification efforts and remediation activities.
Technical Details and Breach Mechanism
Email System Compromise
The breach location identified as "Email" indicates that the primary attack vector involved unauthorized access to one or more email accounts or the email system infrastructure itself. Email system compromises typically occur through several mechanisms: credential theft (phishing, password reuse, or weak authentication), exploitation of unpatched email server vulnerabilities, compromise of email service provider accounts, or insider threats. Given that a business associate was involved, the breach may have originated from a third-party email hosting service, cloud-based email platform, or external vendor system that processes patient communications. Email systems are particularly vulnerable because they often lack the same level of encryption and access controls as dedicated electronic health record (EHR) systems, and they frequently contain unstructured PHI that is difficult to classify and protect comprehensively.
The unauthorized access classification suggests that attackers gained entry to email accounts without authorization, rather than the accounts being lost or stolen devices. This typically indicates either compromised credentials or exploitation of a technical vulnerability. Email breaches of this nature often go undetected for extended periods because email access logs may not be routinely monitored, and attackers can access historical messages without triggering obvious alerts.
Organizational Context
Coppola Physical Therapy and Fitness Gyms operates as a healthcare provider offering physical therapy services and fitness facilities in New Hampshire. The organization's dual focus on clinical physical therapy and fitness services suggests a mid-sized operation serving both rehabilitation patients and wellness-focused community members. Physical therapy clinics typically maintain detailed patient records including medical histories, treatment plans, progress notes, and insurance information. The inclusion of fitness gym operations indicates the organization may also maintain membership records, health assessments, and fitness evaluations. The breach's impact on 632 individuals represents a substantial portion of a typical regional physical therapy and fitness operation's patient and member base.
Patient Impact and Notification
Number of Individuals Affected
The breach impacted 632 individuals, representing patients and potentially members of the fitness facility who had email communications with Coppola Physical Therapy. This moderate-sized breach falls within the range requiring mandatory notification under HIPAA's Breach Notification Rule, which mandates notification to affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach.
Personal Information Involved
Given the email system compromise, the following categories of protected health information may have been exposed:
- Patient Names and Contact Information: Email addresses, phone numbers, and mailing addresses
- Medical Information: Treatment notes, diagnoses, medical histories, and clinical assessments related to physical therapy services
- Insurance Information: Insurance carrier names, policy numbers, and coverage details
- Appointment Details: Scheduling information, appointment times, and clinical visit records
- Payment Information: Billing records, payment methods, and financial account information
- Health Assessment Data: Fitness evaluations, health questionnaires, and wellness screening results
- Demographic Information: Date of birth, gender, and other identifying information
- Communications: Patient-provider correspondence containing sensitive health discussions
The specific data elements exposed depend on which email accounts were compromised and what information was contained in those accounts' message histories and attachments.
HIPAA Compliance and Notification Requirements
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), Coppola Physical Therapy was required to notify affected individuals of the breach without unreasonable delay and no later than 60 calendar days after discovery. The January 31, 2024 submission date to the New Hampshire Attorney General indicates compliance with the mandatory notification timeline. Additionally, the organization must have notified prominent media outlets if the breach affected more than 500 residents of a single jurisdiction, and must have notified the U.S. Department of Health and Human Services Office for Civil Rights (OCR).
The involvement of a business associate triggers additional notification requirements, as the business associate must also notify the covered entity (Coppola Physical Therapy) of the breach, and the covered entity remains responsible for notifying patients even if the breach occurred at the business associate's location or systems.
Industry Context
Email-based breaches represent a significant portion of healthcare data breaches reported annually. According to HHS OCR breach statistics, unauthorized access incidents—particularly those involving email systems—consistently rank among the most common breach types in healthcare. These breaches often result from phishing attacks targeting healthcare workers, credential compromise, or exploitation of email system vulnerabilities. The healthcare industry's reliance on email for clinical communication, combined with the sensitive nature of patient information frequently transmitted via email, creates substantial risk exposure.
Physical therapy clinics and fitness facilities have become increasingly targeted by cybercriminals due to their typically smaller IT security budgets compared to large hospital systems, yet their access to valuable patient health and financial information. The involvement of a business associate in this breach reflects the growing complexity of healthcare data ecosystems, where patient information flows through multiple vendors and service providers, each representing a potential security vulnerability.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Coppola Physical Therapy and Fitness Gyms Breach
Monitor credit reports and financial accounts closely for signs of unauthorized activity. Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review them for accounts or inquiries you did not authorize. Consider placing a fraud alert or credit freeze with the credit bureaus to prevent unauthorized account opening.
Change passwords for all online accounts, particularly email, financial, and healthcare portals. Use strong, unique passwords (minimum 16 characters with mixed case, numbers, and symbols) and enable multi-factor authentication wherever available. If you used the same password across multiple accounts, prioritize changing passwords on financial and email accounts first.
Monitor healthcare accounts and explanation of benefits (EOB) statements for fraudulent claims or services you did not receive. Contact your insurance provider and healthcare providers if you identify suspicious activity. Request copies of your medical records from Coppola Physical Therapy to verify accuracy and identify any unauthorized entries.
Consider enrolling in identity theft protection or credit monitoring services, particularly if Social Security numbers were potentially exposed. Many services offer monitoring for medical identity theft, financial fraud, and dark web activity. Some services are offered free by Coppola Physical Therapy as part of breach remediation; check the breach notification letter for details.
Report any suspected identity theft or fraud to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if you experience financial losses. Document all fraudulent activity with dates, amounts, and account information for potential recovery efforts and insurance claims.
Contact Coppola Physical Therapy directly to confirm what information was exposed in your specific case and request details about the breach investigation, remediation efforts, and any credit monitoring services being offered as part of the breach response.
Be cautious of unsolicited communications claiming to be from Coppola Physical Therapy, your insurance provider, or financial institutions. Verify communications by contacting organizations directly using phone numbers or websites you know to be legitimate, rather than clicking links in emails or responding to phone calls.
Consider consulting with a healthcare attorney or financial advisor if you experience significant identity theft or fraud, particularly if medical identity theft affects your health records or insurance coverage.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New Hampshire Breaches
Search all breaches reported in New Hampshire