Lone Peak Physical Therapy, Inc. Data Breach
Lone Peak Physical Therapy Data Theft Affects 5,809 Patients
What happened in the Lone Peak Physical Therapy, Inc. data breach?
The Lone Peak Physical Therapy, Inc. data breach was reported on December 21, 2023 and affected 5,809 individuals. The breach type was Theft involving Paper/Films. This breach occurred in Montana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Lone Peak Physical Therapy, Inc. Breach Details
Lone Peak Physical Therapy Data Breach Report
Incident Overview
Lone Peak Physical Therapy, Inc., a healthcare provider based in Montana, experienced a significant data breach involving the theft of physical records and films on an unspecified date prior to December 21, 2023, when the breach was formally reported to state authorities. The theft compromised protected health information (PHI) belonging to approximately 5,809 patients. This incident represents a serious breach of patient privacy under the Health Insurance Portability and Accountability Act (HIPAA) and Montana state privacy laws. The theft of paper-based medical records and imaging films—rather than a digital system compromise—underscores the continued vulnerability of physical healthcare documentation in clinical settings.
Discovery and Response Timeline
The exact date of discovery has not been publicly disclosed, but Lone Peak Physical Therapy reported the breach to the Montana Attorney General's office on December 21, 2023. The organization's response included initiating an investigation into the circumstances of the theft, determining the scope of affected individuals, and preparing breach notification letters as required under HIPAA's Breach Notification Rule. Healthcare providers are required to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The organization likely engaged in forensic review of their physical security protocols, access logs, and personnel records to determine how the theft occurred and what preventive measures could be implemented to prevent future incidents.
Specific Details of the Breach
Nature of the Theft
This breach involved the physical theft of paper records and medical films (likely radiographic imaging such as X-rays, MRIs, or CT scans) from Lone Peak Physical Therapy's facilities. Physical document theft remains a significant vulnerability in healthcare settings despite the industry's shift toward electronic health records (EHRs). Paper-based records and films are particularly vulnerable because they can be removed from secure locations without triggering digital alerts or audit trails. The theft likely occurred from a storage area, file room, or clinical workspace where records were maintained. Unlike cybersecurity breaches that may be detected through network monitoring or intrusion detection systems, physical theft may go unnoticed for extended periods until staff conduct inventory audits or patients request their records.
Vulnerability Factors
Physical therapy clinics typically maintain extensive paper documentation including patient intake forms, treatment notes, progress reports, and diagnostic imaging. These records are often stored in areas with varying levels of physical security. Contributing factors to this type of breach may include: inadequate access controls to record storage areas, insufficient surveillance systems, limited staff awareness of security protocols, or opportunistic theft by individuals with legitimate access to the facility. The fact that films were stolen alongside paper records suggests the theft was either targeted (someone knew what they were looking for) or opportunistic (materials were readily accessible and portable).
Organizational Context
Lone Peak Physical Therapy, Inc. is a physical therapy provider operating in Montana. Physical therapy clinics are outpatient rehabilitation facilities that treat patients with musculoskeletal injuries, post-surgical recovery, chronic pain conditions, and mobility disorders. These organizations maintain comprehensive medical records documenting patient history, diagnoses, treatment plans, and progress notes. The clinic's service area encompasses communities in Montana, likely including the Lone Peak region (which spans parts of Madison and Gallatin counties). As a healthcare provider, Lone Peak Physical Therapy is a HIPAA-covered entity responsible for protecting all patient PHI and implementing administrative, physical, and technical safeguards as required by the HIPAA Security Rule.
Patient Impact and Notification
Number of Affected Individuals
Approximately 5,809 patients had their protected health information compromised in this breach. This represents a substantial patient population, likely accumulated over several years of clinical operations. The breach notification process required the organization to identify all affected individuals, compile accurate contact information, and prepare detailed breach notification letters explaining what information was compromised, what steps the organization is taking in response, and what actions patients should take to protect themselves.
Information Compromised
The stolen paper records and films likely contained multiple categories of sensitive health information including: patient names, dates of birth, addresses, telephone numbers, insurance information, Social Security numbers (if used for patient identification), medical diagnoses and treatment histories, physical examination findings, treatment plans and progress notes, medication lists, emergency contact information, and diagnostic imaging (X-rays, MRI, or CT scans). Depending on the clinic's documentation practices, records may have also included information about comorbid conditions, surgical histories, family medical history, and occupational/functional status. The combination of demographic data with detailed medical information creates significant risk for identity theft and medical fraud.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities must notify affected individuals of breaches of unsecured PHI. The rule defines a breach as "the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information." Physical theft of medical records clearly meets this definition. Healthcare providers must implement physical safeguards under the HIPAA Security Rule (45 CFR § 164.310), including facility access controls, workstation use policies, workstation security, and device and media controls. This incident suggests potential gaps in Lone Peak Physical Therapy's physical safeguard implementation.
Physical document theft remains a persistent vulnerability in healthcare despite increased digitization. According to breach statistics, theft accounts for approximately 10-15% of reported healthcare data breaches annually, with paper records representing a significant portion of these incidents. The 5,809 affected individuals places this breach in the medium-to-high impact category for a single facility. Patients should be aware that their medical information may be used for identity theft, fraudulent insurance claims, or sold to third parties on the black market.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Lone Peak Physical Therapy, Inc. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements from your health insurance provider for unauthorized claims or services you did not receive. Contact your insurance company immediately if you identify fraudulent activity.
Monitor medical bills and healthcare provider statements for charges related to services you did not receive. Request copies of your medical records from Lone Peak Physical Therapy and other providers to verify accuracy.
Consider enrolling in credit monitoring and identity theft protection services, particularly those that include medical identity theft monitoring. Many breach victims are offered complimentary monitoring services by the affected organization.
Place a fraud alert with the Federal Trade Commission (FTC) and file a report at IdentityTheft.gov if you suspect identity theft has occurred. Keep detailed records of all fraudulent activity.
Change passwords for any online healthcare portals or accounts associated with Lone Peak Physical Therapy or your health insurance provider.
Contact Lone Peak Physical Therapy directly to confirm receipt of breach notification and request information about what specific records were stolen and what protective measures they are implementing.
Consider consulting with a healthcare attorney if you experience significant financial or medical harm as a result of this breach.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Montana Breaches
Search all breaches reported in Montana