On Jan. 16, 2025, Mid South Rehab Services Inc. discovered unauthorized activity involving an employee’s email account. An investigation took place and it was determined that a cybercriminal gained access to two employee email accounts and viewed or accessed certain emails and attachments containing sensitive information.
A review determined that that data breach compromised both personally identifiable information (PII) and protected health information (PHI). Exposed information included names, Social Security numbers, dates of birth, medical records and health information.
The total number of current and former patients affected by the breach has not been announced. Mid South Rehab published a Notice of Data Privacy Event on its website and is notifying impacted individuals by mail.
The company quickly secured the account and launched an investigation with outside computer specialists to determine the full extent of the incident. It was later determined that an unknown actor had gained access to two employee email accounts and viewed certain emails and attachments within those accounts.
The exposure of both Social Security numbers and health information puts current and former patients at risk for identity theft and fraud.
Upon discovering the unauthorized access, Mid South Rehab Services Inc. secured the affected email accounts and notified federal law enforcement. The company has also set up a dedicated assistance line for affected individuals with questions at 601-605-6777, Monday through Friday between the hours of 8:00 a.m. and 5:00 p.m. Central time, excluding holidays
If you receive notification from Mid South Rehab, you may want to:
For more details about the company, visit the Mid South Rehab Services Inc website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.