East Hawaii Rehab, Inc. DBA Lehua Physical Therapy and Rehab Data Breach
East Hawaii Rehab Data Theft Affects 8,472 Patients
What happened in the East Hawaii Rehab, Inc. DBA Lehua Physical Therapy and Rehab data breach?
The East Hawaii Rehab, Inc. DBA Lehua Physical Therapy and Rehab data breach was reported on February 28, 2025 and affected 8,472 individuals. The breach type was Theft involving Other, Other Portable Electronic Device, Paper/Films. This breach occurred in Hawaii. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
East Hawaii Rehab, Inc. DBA Lehua Physical Therapy and Rehab Breach Details
East Hawaii Rehab Data Breach Report
Incident Overview
East Hawaii Rehab, Inc., operating under the DBA Lehua Physical Therapy and Rehab, experienced a significant data breach involving the theft of patient records on an unspecified date prior to the February 28, 2025 submission to the Hawaii Attorney General's office. The breach involved the unauthorized removal of portable electronic devices and paper-based patient records containing protected health information (PHI) from the organization's facilities. This incident represents a serious compromise of patient privacy affecting thousands of individuals who sought rehabilitation and physical therapy services at the organization's Hawaii-based locations.
Discovery and Response Timeline
The exact date of discovery has not been publicly disclosed in the breach notification submission, though the formal notification to affected individuals and regulatory authorities occurred by February 28, 2025. East Hawaii Rehab initiated an investigation into the theft upon discovery, which likely included a comprehensive audit of missing records, assessment of what information was contained on the stolen devices and documents, and determination of the scope of affected individuals. The organization proceeded with mandatory HIPAA breach notification requirements, notifying affected patients, the Hawaii Attorney General, and potentially the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as required by 45 CFR §164.400-414. The investigation determined that 8,472 individuals had their personal health information potentially compromised through this incident.
Breach Mechanism and Technical Details
This breach involved multiple vectors of data exposure: portable electronic devices (such as laptops, tablets, or mobile devices) and paper-based records. The theft of portable electronic devices represents a common vulnerability in healthcare settings, as these devices often contain cached or stored patient data and may lack adequate encryption or access controls. Paper records, while seemingly low-tech, remain a significant source of PHI exposure in healthcare organizations. The combination of both electronic and physical document theft suggests either opportunistic theft of available materials or a more targeted effort to obtain comprehensive patient information. Portable devices stolen from healthcare facilities typically contain unencrypted patient data, clinical notes, appointment information, and potentially insurance details. Paper records may include intake forms, medical histories, treatment plans, and billing information. The lack of specification regarding encryption status of the devices raises concerns about the ease with which stolen data could be accessed by unauthorized parties.
Organizational Context
East Hawaii Rehab, Inc. operates as a physical therapy and rehabilitation services provider in Hawaii under the brand name Lehua Physical Therapy and Rehab. The organization provides outpatient rehabilitation services to patients recovering from injuries, surgeries, and various medical conditions. As a healthcare provider subject to HIPAA regulations, the organization is required to maintain appropriate safeguards for patient information, implement access controls, and conduct regular risk assessments. The breach of 8,472 patient records indicates a facility or network of facilities with substantial patient volume, suggesting multiple locations or a significant patient base across the Hawaii region. The organization does not appear to have engaged a business associate in this breach, indicating the stolen data was directly under the organization's control and responsibility.
Patient Impact and Affected Population
Approximately 8,472 patients of East Hawaii Rehab's physical therapy and rehabilitation services had their personal health information potentially compromised through this theft. These individuals likely include current and former patients who received services at the organization's facilities. The affected population may span several years of patient records, depending on the scope of the stolen devices and documents. Patients affected by this breach should assume that their information may have been accessed by unauthorized individuals, though the actual use of stolen data remains unknown at this time. The notification process, completed by February 28, 2025, provided affected individuals with information about the breach, the types of data potentially exposed, and recommended protective measures. HIPAA regulations require that such notifications be provided without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Industry Context and HIPAA Implications
Theft of patient records and portable electronic devices remains one of the most common causes of healthcare data breaches, according to HHS OCR breach statistics. Unlike sophisticated cyberattacks, theft of physical and electronic records often results from inadequate physical security controls, insufficient device management policies, and lack of encryption on portable devices. HIPAA's Security Rule (45 CFR §164.300-318) requires covered entities to implement administrative, physical, and technical safeguards to protect ePHI, including encryption of data at rest and in transit, access controls, and audit controls. The presence of unencrypted portable devices and unsecured paper records in this breach suggests potential gaps in the organization's physical security measures and device management protocols. Healthcare organizations are increasingly required to implement mobile device management (MDM) solutions, enforce encryption on all devices containing PHI, and establish strict policies regarding the removal of patient records from secure facilities. This incident underscores the importance of comprehensive security awareness training for all staff members and the implementation of technical controls to prevent unauthorized access to sensitive patient information.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the East Hawaii Rehab, Inc. DBA Lehua Physical Therapy and Rehab Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and insurance claims for any services you did not receive. Contact your insurance provider immediately if you identify fraudulent claims or unauthorized medical services billed to your account.
Monitor financial accounts, including bank accounts and credit cards, for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
Consider enrolling in credit monitoring or identity theft protection services, particularly those that include monitoring of the dark web and underground forums where stolen data is often traded or sold.
Contact East Hawaii Rehab directly to confirm what specific information was on the stolen devices and documents, and request written confirmation of the types of data potentially exposed to your account.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and obtain an Identity Theft Report for your records.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify any requests for personal information by contacting the organization directly using a known phone number or website.
Consider placing a security freeze on your credit file if you have not already done so, which prevents creditors from accessing your credit report without your explicit authorization.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Hawaii Breaches
Search all breaches reported in Hawaii