United Seating and Mobility, L.L.C., d/b/a Numotion Data Breach
Numotion Network Server Breach Affects 602K Patients
What happened in the United Seating and Mobility, L.L.C., d/b/a Numotion data breach?
The United Seating and Mobility, L.L.C., d/b/a Numotion data breach was reported on May 1, 2024 and affected 602,265 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Tennessee. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
United Seating and Mobility, L.L.C., d/b/a Numotion Breach Details
Numotion Data Breach Report
Opening Summary
United Seating and Mobility, L.L.C., operating under the brand name Numotion, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the Tennessee Department of Health on May 1, 2024, affecting approximately 602,265 individuals. Numotion is a major provider of mobility equipment and seating solutions, serving patients across multiple states through a network of retail locations and distribution centers. The unauthorized access to the network server likely exposed protected health information (PHI) and personal data maintained in the company's electronic health records and patient management systems.
Company Response and Investigation Timeline
Upon discovery of the unauthorized access to its network server, Numotion initiated an immediate investigation to determine the scope and nature of the breach. The company engaged cybersecurity professionals to conduct forensic analysis of the compromised systems and identify what information may have been accessed by unauthorized parties. Following standard HIPAA breach notification requirements, Numotion began the process of notifying affected individuals and regulatory authorities. The submission date of May 1, 2024, indicates the formal notification to the Tennessee Department of Health occurred approximately at this time, triggering the required 60-day notification window for affected patients. The company's response included securing the compromised network infrastructure, implementing additional security controls, and conducting a comprehensive audit of system access logs to determine the full extent of the incident.
Technical Details of the Breach
The breach occurred at the network server level, which typically indicates that attackers gained unauthorized access to centralized systems where patient data is stored and processed. Network server compromises of this magnitude often result from vulnerabilities such as unpatched software, weak authentication credentials, phishing attacks targeting employee accounts with administrative privileges, or exploitation of misconfigured cloud storage or remote access systems. The fact that this breach affected over 600,000 individuals suggests the compromised servers contained consolidated patient records across multiple locations or service lines. Network-level breaches are particularly concerning because they can provide attackers with broad access to multiple data repositories simultaneously, rather than isolated patient files. The investigation likely focused on determining the attack vector, the duration of unauthorized access, and whether any data was exfiltrated or merely accessed.
Organizational Context
Numotion operates as a significant player in the durable medical equipment (DME) and mobility solutions industry, providing wheelchairs, seating systems, and related equipment to patients with mobility challenges. The company maintains a substantial operational footprint with multiple locations across the United States, including retail showrooms, distribution centers, and administrative offices. As a healthcare-related entity handling patient information, Numotion is subject to HIPAA regulations and must maintain appropriate safeguards for protected health information. The scale of operations—serving hundreds of thousands of patients—requires strong information technology infrastructure and security protocols. The breach of this magnitude indicates that the company's network infrastructure contained centralized patient databases accessible from multiple points within the organization, a common architecture for large healthcare service providers managing patient records, insurance information, and medical equipment orders across distributed locations.
Patient Impact and Affected Populations
Approximately 602,265 individuals were affected by this breach, making it one of the larger healthcare data breaches reported in 2024. The affected population likely includes current and former patients who received mobility equipment or seating solutions from Numotion, as well as individuals whose information was maintained in the company's patient management systems. These individuals received notification of the breach in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 days after discovery of a breach. The notification process included information about the types of data potentially exposed, recommended protective measures, and details about any credit monitoring or identity theft protection services offered by the company. Given the size of the affected population and the nature of the data involved, Numotion likely offered some form of complimentary credit monitoring or identity theft protection services as part of its breach response.
Data Exposure and Information Types
While the specific data elements exposed were not detailed in the breach submission, network server breaches at healthcare organizations typically result in exposure of multiple categories of protected health information. Likely exposed data may include: names, addresses, telephone numbers, email addresses, dates of birth, Social Security numbers, insurance information including policy numbers and group numbers, medical record numbers, diagnoses and treatment information related to mobility needs, prescription information, payment card data or banking information used for billing purposes, and potentially driver's license numbers or other government-issued identification. The exposure of this combination of data types creates significant risk for identity theft, insurance fraud, and medical identity theft. Patients whose Social Security numbers and financial information were exposed face heightened risk of fraudulent account creation and unauthorized use of their personal information.
HIPAA Compliance and Regulatory Context
As a covered entity or business associate handling protected health information, Numotion is required to comply with HIPAA Security Rule standards, which mandate administrative, physical, and technical safeguards to protect patient data. The breach notification rule requires covered entities to notify affected individuals, the media (if more than 500 residents of a state are affected), and the Secretary of Health and Human Services. Network server breaches represent a common vulnerability in healthcare IT environments, with attackers increasingly targeting centralized systems that provide access to large volumes of patient data. The 602,265 individuals affected by this breach exceeds the 500-person threshold requiring media notification, indicating this incident received public reporting and regulatory scrutiny. Healthcare organizations have experienced a significant increase in network-based attacks in recent years, with cybercriminals targeting the valuable health information maintained in electronic health record systems and patient databases. The breach underscores the importance of implementing multi-factor authentication, network segmentation, regular security assessments, and prompt patching of known vulnerabilities in healthcare IT infrastructure.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the United Seating and Mobility, L.L.C., d/b/a Numotion Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and insurance claims for unauthorized medical services or equipment; contact your insurance provider immediately if you identify suspicious activity
Monitor financial accounts and payment cards for unauthorized transactions; consider changing passwords for online banking and healthcare portals; enable transaction alerts with your financial institutions
Watch for suspicious communications claiming to be from healthcare providers, insurance companies, or medical equipment suppliers; verify any requests for personal information directly with the organization using contact information from official sources rather than information provided in unsolicited communications
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Tennessee Breaches
Search all breaches reported in Tennessee
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits