ILSocial EngineeringHealthcareHealthcarePhishingStolen CredentialsBusiness Associate (HIPAA)Customer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Thrive Physical Therapy Partners
bd_d98bd71cd9564399 · schema v1 · pii pii-v1
Full breach record for Thrive Physical Therapy Partners →Thrive Physical Therapy Partners (a Business Associate, IL) reported to HHS on 2025-04-16 a Hacking/IT Incident affecting 986 individuals. An employee was the target of an email phishing scheme that compromised PHI including demographic, clinical, and financial information. Breached information was located in Email. The BA notified HHS, impacted individuals, and the media, and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance regarding the HIPAA Rules.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a54e2cef35f5db73Indiana State AGfiled 2025-04-14(2d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 16, 2025
- Raw hash
- cd8ee6a5e3adad7c90f17e51e6ec138e3805a17ddc0640cfb5ff5f3c2d935ec3
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Thrive Physical Therapy Partnersnorm: thrive physical therapy
- Industry
- Business Associate
Victim entity
- Name
- Thrive Physical Therapy Partnersnorm: thrive physical therapy
- Industry
- Business Associate
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 986
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR provided technical assistance regarding the HIPAA Rules
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.