Cooper Aerobics notifies patients almost a year after network intrusion
- Organization
- Cooper Aerobics
- Exploit
- Hacking
- Industry
- Healthcare
Cooper Aerobics, the Dallas based wellness group that operates Cooper Clinic, P.A., Cooper Medical Imaging, LLP and Cooper Aerobics Enterprises, Inc., began notifying individuals on January 5, 2024 about a data security incident that had occurred almost a year earlier.
According to the company, an unauthorized party accessed its network on February 3, 2023 and potentially removed files. Cooper Aerobics said it contained the intrusion on discovery, engaged outside data security specialists, and confirmed on March 19, 2023 that files had been taken. The review to identify whose information was in those files was not completed until December 8, 2023, which the company gave as the reason for the gap between the incident and the notifications.
The categories of data listed were unusually broad. They included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, taxpayer identification numbers, driver's license and other government identification numbers, passport numbers, financial account and routing numbers, payment card numbers and expiration dates, usernames and passwords, and health information such as medical records, patient account numbers, prescription details and insurance information. Not every item applied to every person.
Cooper Aerobics offered complimentary credit monitoring to individuals whose Social Security numbers were involved and filed breach notices with state regulators, including California. It said it had no evidence at the time of notification that the data had been misused. News reports based on Cooper's notice to the state attorney general put the number affected at 89,399, and the class action settlement covering all three Cooper entities put the number who received notification letters at 117,925. Several plaintiffs' firms opened investigations within weeks.