Restorative Therapies, Inc. Data Breach Exposes Health Records

Published: 25 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Restorative Therapies, Inc. notified the Vermont Attorney General in September 2026 that health records were involved in a data breach. The exact number of affected individuals and how the breach occurred have not been publicly disclosed. Anyone who received services from the company should monitor medical statements and credit reports closely, and consider a fraud alert as a precaution.

CompanyRestorative Therapies, Inc.
IndustryHealthcare
Data Types ExposedHealth Records
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Restorative Therapies Data Breach?

Restorative Therapies, Inc. filed a formal data breach notification with the Vermont Attorney General in September 2026. The filing confirms that health records tied to individuals served by the company were involved in the incident. This disclosure is what triggered public awareness of the Restorative Therapies data breach.

The exact discovery date has not been publicly disclosed. Because the notification names health records as the only confirmed data category, the incident appears to involve either unauthorized access to patient information systems or a compromise of files containing medical data. However, the specific attack method used to gain access has not been made public.

As a result, many details that consumers typically want, such as how attackers got in or how long the exposure lasted, remain unknown at this time. What is confirmed is that Restorative Therapies took the step of notifying Vermont’s Attorney General, which is generally required once a company confirms that residents’ protected information was compromised. This filing is the clearest evidence so far that real personal data was involved.

Regulatory filings like this one are often the first public signal that a healthcare-related breach occurred. In addition, these filings typically follow an internal review process where the organization first has to confirm which data types were affected before notifying regulators. That process suggests Restorative Therapies had already identified health records as compromised before submitting its notice.

Who was affected?

The individuals affected by this breach appear to be people whose health records were held by Restorative Therapies, Inc. Because the company’s notification centers specifically on health data, those affected are most likely current or former patients, clients, or individuals connected to therapeutic or rehabilitative services the company provides.

The exact number of people affected has not been publicly disclosed. This means residents cannot yet know the full scale of the Restorative Therapies data breach. In addition, the notification was filed with Vermont’s Attorney General, which typically means at least some Vermont residents were affected, though the breach could extend to individuals in other states as well.

It also remains unclear whether the breach reaches minors, since therapeutic and rehabilitative services sometimes serve pediatric patients. Until more information becomes available, anyone who has received services connected to Restorative Therapies should consider themselves potentially affected.

What Information Was Potentially Exposed?

According to the confirmed regulatory filing, the breach involved health records. Health-related information is considered highly sensitive because it often includes details that cannot be changed, unlike a password or account number.

  • Health Records

Because health records can include diagnoses, treatment history, and clinical notes, exposure of this kind of data carries real consequences. For example, individuals could face embarrassment or discrimination if sensitive health details became public or were misused. In addition, exposed medical information can be used to commit medical identity theft, where a criminal uses someone else’s identity to obtain treatment or prescriptions.

Medical identity theft is especially difficult to detect and resolve. As a result, victims may not notice fraudulent activity until they receive a suspicious bill or see unfamiliar entries on an insurance statement. Furthermore, inaccurate medical information added to a victim’s file because of fraud can affect future medical treatment decisions. This makes ongoing monitoring important, even though no financial account numbers or Social Security numbers were listed in this particular filing.

What is the company doing?

Restorative Therapies, Inc. filed a formal breach notification with state regulators, which is a required step once a company confirms that residents’ health data was compromised. This filing shows the company has acknowledged the incident to at least one government authority.

Specifically, the company filed formal notification with the Vermont Attorney General. This filing is part of the standard legal process organizations follow when personal data has been compromised. Beyond confirming the filing itself, the source material does not describe additional remediation steps, credit monitoring offers, or communication plans. Therefore, any further response details have not been publicly disclosed at this time.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should check their credit reports regularly for unfamiliar accounts or inquiries. Even though this breach centers on health records rather than financial account numbers, personal identifying details are often included in medical files. This means the information could still be used to open fraudulent accounts.

You can request free credit reports from each of the three major credit bureaus. Reviewing these reports every few months helps you catch suspicious activity early. If anything looks unfamiliar, dispute it immediately with the bureau involved.

Watch for Signs of Medical Identity Theft

Because health records were involved, individuals should closely review any insurance statements or medical bills they receive. Unexpected charges, unfamiliar providers, or new diagnoses on your file could indicate someone else is using your identity for medical services.

If you notice anything unusual, contact your health insurance provider right away. In addition, request a copy of your medical records to check for entries you don’t recognize. Correcting inaccurate medical information early can prevent complications with future treatment or insurance claims.

Stay Alert for Phishing Attempts

Following any data breach, scammers often send phishing emails or texts pretending to be from the breached company or a related healthcare provider. These messages may ask you to click a link or share personal details.

Because of this, avoid clicking links or downloading attachments from unexpected messages, even if they appear official. Instead, contact the organization directly using a phone number or website you already trust. Being cautious here can prevent a second layer of harm following the original breach.

Consider a Fraud Alert or Credit Freeze

If you’re concerned about identity theft risk, placing a fraud alert on your credit file is a simple, free step. This makes it harder for someone to open new credit accounts using your information.

For stronger protection, you can also request a credit freeze, which restricts access to your credit file entirely. While this adds an extra step when you apply for credit yourself, it offers the strongest safeguard against unauthorized account openings. Given the sensitive nature of health data, this precaution may be worthwhile even without confirmed financial data exposure.

Consult a Data Breach Attorney

Because health information is protected under strict privacy laws, affected individuals may have legal options worth exploring. A data breach attorney can review the details of your situation and explain whether you qualify for compensation.

Many attorneys offer free case evaluations, so there’s little downside to asking questions. This step can also help you understand any relevant deadlines for filing a claim, since these vary depending on where you live and the specific facts of the breach.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Browse all recent data breaches →