[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f22ha3qb15qdr5":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"6a70614221498ce09bd72730","RestorixHealth2024","Restorix Health 2024 Data Breach","restorix-health-2024","restorixhealth.com","2024-05-07T00:00:00.000Z","2026-08-03T09:37:06.716Z","Official Restorix notice, HHS OCR report, and state-filing-based independent reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16,17],"https:\u002F\u002Frestorixhealth.com\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FNotice-of-Security-Incident.pdf","https:\u002F\u002Frestorixhealth.com\u002F",38553,"known",null,"people","Medium",[24,25,26,27,28,29,30,31,32,33,34,35],"Names","Dates of birth","Driver's licenses","Government issued IDs","Passport numbers","Social security numbers","Patient IDs","Medical information","Prescription information","Treatment information","Diagnoses","Health insurance information","\u003Cp>\u003Cstrong>The 2024 Restorix Health data breach\u003C\u002Fstrong> involved unauthorized access to an employee email account between May 7 and May 29, 2024. Restorix learned of the incident on or around May 30, secured the account, and began an investigation with external cybersecurity specialists.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as an email Unauthorized Access\u002FDisclosure incident affecting 38,553 people. Restorix's official notice confirms that identity and health information belonging to people affiliated with its healthcare partners may have been present in the accessed account.\u003C\u002Fp>\u003Ch2>How was the Restorix Health breach confirmed?\u003C\u002Fh2>\u003Cp>Restorix's official notice connects the access window, discovery and review dates, disclosed information types, and organizational response in one event. The HHS OCR entry confirms the Restorix Health identity, its healthcare business-associate role, the email environment, and the current total of 38,553 people.\u003C\u002Fp>\u003Cp>An independent event summary tracking state filings also corroborates the May 7–29 access window, the November 27, 2024 data-review milestone, notice to healthcare partners on December 18, and individual notices beginning February 14, 2025. The disclosed fields varied by person; the 38,553 total does not mean every field applied to everyone.\u003C\u002Fp>\u003Ch2>What happened between May 7 and May 29, 2024?\u003C\u002Fh2>\u003Cp>An unauthorized actor accessed a Restorix employee's email account between May 7 and May 29. Restorix says it learned of the access on or around May 30, secured the account, and engaged specialists to determine the nature and scope of the incident.\u003C\u002Fp>\u003Cp>An extensive investigation and document review determined on November 27 that the accessed account contained personal or protected health information associated with people affiliated with healthcare partners. Public sources do not disclose how the account was compromised, the technical weakness used, or the identity of the responsible actor.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, potentially affected information included first and last names, dates of birth, driver's license numbers, other government identification numbers, passport numbers, and Social Security numbers. Patient identifiers and certificate or license numbers were also listed in the official notice.\u003C\u002Fp>\u003Cp>Health fields may have included medical and prescription information, dates of service, conditions, treatment or diagnoses, and health insurance information. Financial accounts, payment cards, passwords, and notice recipients' email addresses are not added because the official notice does not list them.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity numbers combined with patient and health information can support identity theft, healthcare fraud, or convincing targeted messages. Social Security, passport, and government identification numbers cannot simply be changed, so monitoring may be appropriate over a long period.\u003C\u002Fp>\u003Cp>Someone who knows a real treatment, prescription, service date, or insurance detail may create a more persuasive request claiming to represent Restorix, a hospital, a clinic, or an insurer. Possessing those details does not prove authority, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did Restorix respond?\u003C\u002Fh2>\u003Cp>Restorix secured the accessed account, engaged third-party forensic specialists, and conducted a manual document review to identify involved information. Healthcare partners were informed on December 18, 2024, and notices to people with available mailing addresses began on February 14, 2025.\u003C\u002Fp>\u003Cp>The organization says it implemented additional cybersecurity safeguards, enhanced employee training, and reviewed its policies and procedures. The official account does not characterize the event as ransomware, name a particular actor, or report known misuse of the disclosed information.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review financial accounts, credit reports, and health-insurance explanations for accounts, transactions, services, or claims they do not recognize. Suspicious activity should be reported to the relevant financial institution, healthcare provider, insurer, and authorities when appropriate.\u003C\u002Fp>\u003Cp>Do not share a Social Security number, patient information, password, or one-time verification code in response to an unexpected email, message, or call. A request claiming to come from Restorix or a healthcare organization should be verified using contact information on the official website rather than links or numbers in the message.\u003C\u002Fp>","","Restorix Health 2024 Data Breach (38.6 Thousand People Affected)","The Restorix Health data breach may have exposed identity and health information belonging to 38,553 people.","\u002Fuploads\u002Flogo\u002Frestorix-health-official.svg",false,{"name":43,"sector":44,"country":45,"website":17,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":20},"Restorix Health, Inc.","Healthcare","United States"]