All Breaches
May 8, 2026 Verified Sensitive Record Healthcare

SportsMed Physical Therapy 2026 Data Breach

The SportsMed Physical Therapy 2026 data breach emerged when the New Jersey-based rehabilitation organization discovered suspicious activity related to one employee email account on May 8, 2026. SportsMed immediately opened an investigation; in its July 7 public notice, it said the investigation remained ongoing and that affected data could contain patient information.

Possible data included patient names together with dates of service, provider names, diagnosis information, treatment information, or health-insurance information. The organization does not say every person had the same fields. Because no deduplicated nationwide population was published, LeakData keeps pwnCount and totalRecords at zero, and importedRecordCount is zero because no person rows were obtained.

How Was the SportsMed Physical Therapy Breach Confirmed?

The primary source is SportsMed's “Notice of Data Incident” PDF dated July 7, 2026 on its corporate domain. On the organization's behalf, it explains the discovery date, single employee mailbox, ongoing review, possible data categories, password resets and policy review, misuse assessment, and assistance line.

Claim Depot connects the official PDF with the organization profile and independently summarizes the event. The two sources align on one mailbox, May 8 discovery, and possible patient-name, service-date, provider, diagnosis, treatment, and insurance fields. Although the secondary summary uses “compromised,” LeakData does not take technical certainty beyond the organization's description of suspicious activity.

What Was Discovered on May 8, 2026?

SportsMed identified suspicious activity related to a single employee email account May 8 and immediately began an investigation. The organization said the review was still underway when it published the July 7 notice. As part of its response, it reset passwords and reviewed policies and procedures related to the event.

The public document does not provide start and end times for unauthorized mailbox access, the initial entry method, whether phishing was used, the actor, whether emails were downloaded, a ransom demand, or publication of data. LeakData records the genuine organization disclosure but does not add data-theft or threat-actor claims unsupported by the incomplete investigation.

What Patient and Service Information Was in Scope?

Affected data could contain patient names and one or more dates of service. That combination may reveal a person's care relationship with SportsMed and when services were received. A name and date do not represent an entire clinical file, but authentic visit context can make targeted phishing or fraudulent billing communications more convincing.

The official notice does not list addresses, birth dates, Social Security numbers, emails, telephone numbers, medical-record numbers, or payment cards as event fields. General credit-monitoring recommendations do not prove those data were present. LeakData limits its classes to categories disclosed by SportsMed and does not assume the same information combination for every patient.

How May Diagnosis and Treatment Information Have Been Affected?

SportsMed listed diagnosis information and treatment information among the possible data types. These fields may disclose the context of an illness, injury, rehabilitation plan, or clinical service and constitute protected health information. The organization also said a provider name may have been present, potentially linking a person to a particular clinician or care team.

The public PDF does not separately confirm a specific diagnosis, treatment type, prescription, therapy note, image, laboratory result, dosage, or complete medical record. LeakData does not add those details. Recipients should review patient portals and provider records for unfamiliar appointments, notes, messages, or contact changes and verify suspicious entries directly with the clinic.

What Is the Risk From Health-Insurance Information?

Health-insurance information is another field that may have been present in affected data. This broad category may expose an insurer or plan context and support social engineering about an explanation of benefits, claim, or coverage issue. SportsMed does not separately confirm policy numbers, member numbers, group numbers, claim numbers, or insurance-card images.

Individuals should review explanation-of-benefits statements and online insurance accounts for services, providers, or claims they do not recognize. If a suspicious entry appears, the provider and insurer should be contacted through independently obtained official channels. An unexpected request for payment, a password, or a one-time code is not validated by this event and should not be trusted.

How Many People Were Affected and How Did SportsMed Respond?

SportsMed does not disclose a nationwide affected-person count in its public notice. LeakData does not convert patient volume, mailbox message count, or secondary estimates into a victim population; pwnCount and totalRecords are zero. The organization said it had no indication at notification time that information had been misused. That historical assessment does not rule out future misuse.

SportsMed reset passwords, evaluated event-related policies and procedures, and established the 1-833-851-9744 call center, available weekdays from 8 a.m. to 8 p.m. ET. It recommends monitoring credit reports, account statements, and explanation-of-benefits forms. Sources should be updated if the ongoing investigation changes its conclusions. LeakData does not host incident files or patient records.

0
Affected Accounts
7
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

7
Protected health information
Patient names
Dates of service
Provider names
Diagnosis information
Treatment information
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateMay 8, 2026
Domainspineandsportsmed.com
SourceOfficial SportsMed Physical Therapy notice confirming suspicious activity involving one employee email account and possible exposure of patient and health information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information