CSIDB logo
Incident

Ivy Rehab Physical Therapy

Incident posture

Attack window
May 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-26 00:00

Linked entities

Victim
Ivy Rehab Physical Therapy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Ivy Rehab Physical Therapy experienced a data security breach involving unauthorized access to employee email accounts due to a presumed phishing campaign. The compromised accounts contained patient information, including names combined with protected health details, Social Security numbers, or financial account data. The organization found no evidence of misuse but notified affected individuals and offered complimentary credit monitoring and identity theft restoration services. In response, the company implemented enhanced security measures such as frequent password changes, ongoing staff training, and improved data protection protocols to prevent future incidents.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2019, Ivy Rehab Physical Therapy detected evidence suggesting unauthorized access to a limited number of employee email accounts. The organization immediately engaged its internal IT team to investigate, which confirmed that unknown parties had compromised certain accounts. A subsequent forensic investigation by an external cybersecurity firm determined the unauthorized access resulted from a presumed phishing campaign targeting employees. The investigation revealed attackers infiltrated the email system between May and September 2019, though the exact intrusion timeline remained unspecified. On September 26, 2019, after completing a comprehensive review of affected accounts, Ivy Rehab confirmed the compromised mailboxes contained sensitive patient information. The organization found no evidence of actual misuse or attempted exploitation of the accessed data during this period.

The compromised information included current and former patients' first and last names combined with protected health information, Social Security numbers, or financial account details. While no fraudulent activity was detected, Ivy Rehab initiated notifications on November 26, 2019, offering complimentary credit monitoring and identity theft restoration services through Equifax for potentially affected individuals. Response measures included mandatory frequent password changes for all staff, enhanced security awareness training programs, and continued collaboration with government agencies. The organization implemented additional investments in data protection capabilities but did not disclose specific technical controls. Ivy Rehab's Chief Compliance Officer publicly acknowledged the breach, emphasizing ongoing efforts to strengthen security protocols while apologizing for potential patient concerns.

Sources

Sources available to members: 1 source.

CSIDB