California based healthcare facility recently suffered data breach

November 5th, 2016 by admin Leave a reply »

Physical therapy organization recently suffered a data breach. The incident has potentially affected the information of approximately 8,000 individuals.

As per the reports, Silver Creek Fitness & Physical Therapy, Silver Creek Physical Therapy Gilroy, Silver Creek Physical Therapy Sunnyvale, and Silver Creek Physical Therapy Los Gatos (Silver Creek) billing and software companies reported to Silver Creek about the vulnerability of Amazon “S3” storage account.

The incident provided the access to individuals outside of the organization. Various facilities mentioned that the account was vulnerable from May 2016 to September 11, 2016. Facility also said that some PHI was in the storage account.

Affected information includes patient names, Medicare numbers, prescriptions, dates of birth, treatment locations, treatment dates, Social Security numbers for a small subset of individuals, driver’s license numbers, and progress notes. As per the OCR data breach reporting tool, total 8,009 individuals were affected.

“We take any threat to the security of information entrusted to us very seriously,” Co-founder of Silver Creek Fitness & Physical Therapy Todd Jones said in a statement.  “Once the error was discovered, we worked with the billing and software companies to ensure that access to the storage account was restricted and that proper access credentials are in place. We apologize for any inconvenience or concern this incident may cause our patients.”

Facility mentioned that it is unaware of any misuse of client personal information. It is offering credit monitoring and identity restoration services.

Fraud prevention tips for the affected individuals includes:

Review of account statements, medical bills, and health insurance statements

Credit reports monitoring

Placing credit file fraud alert activation

Placing credit file security freeze

It’s also important to educate on identity theft, fraud alerts, and the steps to protect by contacting the Federal Trade Commission or your state Attorney General.


Alertsec’s cloud-based information security service provides an easy and convenient way to protect information on your organization’s laptops and computers.


Leave a Reply