Sport and Spine Rehab
Disclosed Aug 1, 20179 years ago31,120 affectedConfirmed
Sport and Spine Rehabilitation, the covered entity (CE), reported that on June 3, 2017, through remote access, a cyber attacker successfully executed a ransomware attack that encrypted the data stored on its computer servers, potentially affecting 34,000 individuals. The types of protected health information (PHI) that were involved included patients’ names, addresses, dates of birth, social security numbers, and medical information. The CE immediately shut down the computer network and contracted with Lore Systems, Inc. to perform a full security sweep of the server infrastructure and perform a number of corrective actions. Lore Systems, Inc. informed the CE that the attack infected the “cloud” server, at which point files were encrypted on the CE’s virtual office server (VOS) through the mapped network drive. The CE confirmed that all encrypted files were limited to just the data folder on the VOS server. The CE provided breach notification to HHS, affected individuals, and the media. The CE hired Provendatarecovery.com to restore the files to their original locations and ensure the computer server environment was clean. The CE indicated that manual scans across all devices are p
What is known
| People affected | 31,120 (as reported to HHS) |
|---|---|
| Disclosed | Aug 1, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Sport and Spine Rehab (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 1, 2017 | 31,120 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.