[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f33rrythydclgh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a705ea3cb36f6c7b8c37bc2","FyzicalAcquisitionHoldings2024","FYZICAL 2024 Data Breach","fyzical-acquisition-holdings-2024","fyzical.com","2024-12-09T00:00:00.000Z","2026-08-03T09:25:55.841Z","Official organization notice, HHS OCR report, and state-filing-based independent reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16,17,18],"https:\u002F\u002Fwww.fyzical.com\u002Fclient\u002F996\u002Fmedia\u002Ffile\u002F400274\u002FFyzical_Website_Notice_dec22_2025.pdf","https:\u002F\u002Fmm.nh.gov\u002Ffiles\u002Fuploads\u002Fdoj\u002Fremote-docs\u002Ffyzical-acquisition-20251219.pdf","https:\u002F\u002Fwww.fyzical.com\u002F",43045,"known",null,"people","Medium",[25,26,27,28,29,30,31,32],"Names","Dates of birth","Social security numbers","Government issued IDs","Financial information","Payment card information","Health insurance information","Medical information","\u003Cp>\u003Cstrong>The 2024 FYZICAL data breach\u003C\u002Fstrong> came to light after Fyzical Acquisition Holdings, the parent company of FYZICAL Therapy &amp; Balance Centers, detected unusual activity in its email environment on December 9, 2024. The investigation found that some email data may have been viewed or copied without authorization.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights lists the event as an email Hacking\u002FIT Incident affecting 43,045 people. The organization's official notice confirms that identity, financial, and health information may have been involved, with the affected fields varying by person.\u003C\u002Fp>\u003Ch2>How was the FYZICAL breach confirmed?\u003C\u002Fh2>\u003Cp>Fyzical Acquisition Holdings' official notice connects the December 9, 2024 discovery date, possible unauthorized access to email data, completion of the data review on November 25, 2025, and the disclosed information types in one event. The HHS OCR entry confirms the organization, the email environment, and the current total of 43,045 people.\u003C\u002Fp>\u003Cp>An independent event summary also describes the documents filed with state authorities, the incident timeline, and the disclosed fields. The 1,801 people reported for Texas are a state subset of the same incident, not a separate event or an additional figure to add to the nationwide HHS total of 43,045.\u003C\u002Fp>\u003Ch2>What was detected on December 9, 2024?\u003C\u002Fh2>\u003Cp>The organization identified unusual activity in its email environment on December 9 and began an investigation to understand the nature and scope of the event. The investigation concluded that some email data may have been viewed or copied without authorization as part of the incident.\u003C\u002Fp>\u003Cp>The public notice does not disclose when access began, which accounts or technical weakness were used, or the identity of the responsible actor. December 9 is therefore recorded as the discovery date rather than presented as a confirmed first-access date or access-window boundary.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, potentially affected information included names, dates of birth, Social Security numbers, and driver's license or state identification numbers. Financial account and payment-card information also appear among the fields disclosed in the official notice.\u003C\u002Fp>\u003Cp>Health insurance and medical health information may also have been involved. The organization specifically says not every field applied to every person; email addresses and passwords are not added because they are not among the publicly disclosed information types.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity numbers combined with financial and health information can support identity theft, fraudulent account opening, payment fraud, or convincing targeted messages. Because Social Security and government identification numbers cannot simply be changed, monitoring may be appropriate over a long period.\u003C\u002Fp>\u003Cp>Someone who knows a real treatment, insurance, or financial detail may create a more persuasive request claiming to represent FYZICAL, a healthcare provider, a bank, or a government agency. Possessing those details does not prove authority, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Fyzical Acquisition Holdings reviewed the email data to identify affected information and people, completing that comprehensive review on November 25, 2025. Notices were mailed to people with available addresses, and eligible individuals were offered credit monitoring and identity-protection services.\u003C\u002Fp>\u003Cp>The organization also says it reviewed and enhanced existing policies and procedures. Public sources do not characterize the event as ransomware, name a responsible group, or state that every potentially affected field was definitively copied.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports, financial accounts, and health-insurance explanations for accounts, transactions, services, or claims they do not recognize. Suspicious activity should be reported to the relevant financial institution, insurer, and authorities when appropriate.\u003C\u002Fp>\u003Cp>Do not provide a Social Security number, card information, password, or one-time verification code in response to an unexpected email, message, or call. A request claiming to come from FYZICAL or another organization should be verified using contact information on the official website rather than links or numbers in the message.\u003C\u002Fp>","","FYZICAL 2024 Data Breach (43 Thousand People Affected)","The FYZICAL data breach may have exposed identity, financial, and health data belonging to 43,045 people.","\u002Fuploads\u002Flogo\u002Ffyzical-official-logo.png",false,{"name":40,"sector":41,"country":42,"website":18,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Fyzical Acquisition Holdings, LLC","Healthcare","United States"]