VibrantCare Rehabilitation
Disclosed Feb 8, 20206 years ago1,668 affectedConfirmed
VibrantCare Rehabilitation, the covered entity (CE), reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of 1,655 individuals. The ePHI involved included names, Social Security numbers, addresses, drivers’ license information, birthdates, diagnoses, lab results, medications prescribed, financial information, and claims information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards and retrained its staff on the proper methods of identifying fraudulent email communications.
What is known
| People affected | 1,668 (as reported by the organization) |
|---|---|
| Disclosed | Feb 8, 2020 |
| Discovered | Dec 11, 2019 |
| Happened | Aug 20, 2019 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: VibrantCare Rehabilitationoag.ca.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: VibrantCare Rehabilitationmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): VibrantCare Rehabilitation (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 8, 2020 | 1,655 |
| California AGresidents of CA | Feb 24, 2020 | |
| Maine AGresidents of ME | Feb 24, 2020 | 1 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · disclosed: 2020-02-24 to 2020-02-08 · backfill source
- 2026-09-25 · summary: empty to VibrantCare Rehabilitation, the covered entity (CE), reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information (ePHI) of 1,655 individuals. The ePHI involved included name · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 1668 · backfill source
- 2026-09-25 · discovered: empty to 2019-12-11 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.