Fyzical Acquisition Holdings, LLC Data Breach
Fyzical Fitness Chain Email Breach Affects 43K Members
What happened in the Fyzical Acquisition Holdings, LLC data breach?
The Fyzical Acquisition Holdings, LLC data breach was reported on March 21, 2025 and affected 43,045 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Fyzical Acquisition Holdings, LLC Breach Details
Fyzical Acquisition Holdings Data Breach Report
Incident Overview
Fyzical Acquisition Holdings, LLC, a Florida-based fitness and physical therapy organization, experienced a significant data breach involving unauthorized access to its email systems. The breach was reported to the U.S. Department of Health and Human Services on March 21, 2025, affecting approximately 43,045 individuals. The unauthorized access to email systems represents a common but serious attack vector in healthcare-related organizations, where patient communications, appointment details, and potentially protected health information (PHI) may be stored or transmitted through email platforms.
Discovery and Response Timeline
While specific discovery dates are not provided in the breach submission, the March 21, 2025 submission date indicates the entity reported the incident to HHS within the required 60-day notification window mandated by HIPAA Breach Notification Rule. The involvement of a business associate in this breach suggests that Fyzical Acquisition Holdings likely engaged a third-party vendor for email hosting, IT services, or related infrastructure. The entity's notification to HHS demonstrates compliance with mandatory breach reporting requirements, though the specific investigation timeline and remediation steps undertaken remain part of the entity's internal documentation.
Technical Breach Details
Email system breaches typically occur through several common vectors: credential compromise (phishing, weak passwords, or credential stuffing), unpatched software vulnerabilities, misconfigured email servers, or compromised business associate systems. Given that a business associate was involved, the breach may have originated from a third-party vendor's infrastructure rather than Fyzical's direct systems. Email breaches are particularly concerning in healthcare settings because email often contains sensitive patient information including appointment scheduling details, medical history references, billing information, and communications between patients and healthcare providers. The email location designation indicates that attackers gained access to mailboxes, potentially allowing them to view, copy, or exfiltrate messages spanning months or years depending on email retention policies.
Organizational Context
Fyzical Acquisition Holdings, LLC operates as a fitness and physical therapy franchise network with locations across multiple states, including significant presence in Florida. The organization provides physical rehabilitation services, fitness training, and wellness programs to members and patients. As a healthcare-adjacent organization providing physical therapy services, Fyzical is subject to HIPAA regulations and must maintain appropriate safeguards for protected health information. The scale of operations—affecting over 43,000 individuals—indicates a substantial membership and patient base across numerous franchise locations. The involvement of a business associate in the breach highlights the complexity of modern healthcare IT infrastructure, where organizations often rely on external vendors for critical systems like email hosting and data management.
Impact and Affected Individuals
Approximately 43,045 individuals were affected by this breach, representing a significant regional incident. The affected population likely includes current and former members, patients receiving physical therapy services, and potentially employees. Given the email system compromise, individuals' information may have been exposed depending on what data was stored in or transmitted through email systems. The breach notification process, required under HIPAA, mandates that Fyzical provide affected individuals with details about the breach, the types of information exposed, steps the organization is taking to address the incident, and recommended protective measures. Notification typically occurs via mail, email, or other appropriate means within 60 days of discovery.
Data Exposure and Privacy Implications
Email system breaches in healthcare organizations typically expose multiple categories of information. Depending on email content and attachments, exposed data may include: names, addresses, phone numbers, email addresses, dates of birth, membership or patient identification numbers, appointment scheduling information, medical history references, treatment notes or summaries, billing and insurance information, and potentially Social Security numbers or financial account details if included in email communications. The specific data exposed depends on what information was included in the compromised email accounts and the scope of the unauthorized access. Patients and members should assume that any information they communicated via email to Fyzical or that Fyzical sent to them via email may have been accessed by unauthorized parties.
HIPAA Compliance and Industry Context
This breach underscores ongoing challenges in healthcare cybersecurity. Email remains a primary attack vector for healthcare data breaches, accounting for a significant percentage of reported incidents annually. HIPAA requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect PHI, including encryption of data in transit and at rest, access controls, audit logging, and incident response procedures. The involvement of a business associate in this breach raises questions about vendor management and oversight—covered entities remain liable for business associate breaches and must ensure contracts include appropriate security requirements and breach notification obligations. Similar email-based breaches have affected numerous healthcare organizations, fitness chains, and medical practices, demonstrating the persistent vulnerability of email systems despite available security technologies like multi-factor authentication and email encryption.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Fyzical Acquisition Holdings, LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze to prevent unauthorized credit applications.
Review financial accounts, credit card statements, and bank records regularly for unauthorized transactions. Contact financial institutions immediately if suspicious activity is detected.
Monitor medical records and explanation of benefits (EOB) statements from insurance providers for unauthorized medical services or claims. Contact healthcare providers and insurers if unfamiliar charges appear.
Change passwords for email accounts and any online accounts associated with Fyzical or related services, using strong, unique passwords. Enable multi-factor authentication where available.
Be vigilant against phishing emails and social engineering attempts. Verify requests for personal or financial information by contacting organizations directly using known phone numbers or websites.
Consider enrolling in credit monitoring or identity theft protection services if offered by Fyzical or available through personal insurance or employer benefits.
Document all communications related to the breach and keep records of any fraudulent activity discovered, including dates, amounts, and actions taken.
Report any suspected identity theft or fraud to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if necessary.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits