started · updated
RIZAP Group apologizes for leaking sensitive health data to generative AI
RIZAP Group has issued an apology after an employee mistakenly uploaded sensitive customer data to a personal generative AI service. The incident involved data from the company’s health guidance management system, covering a period from January 1 to August 19.
The leaked information included names, dates of birth, genders, email addresses, and insurance card numbers. For some individuals, addresses and phone numbers were also included. Notably, the data contained sensitive health information, such as diagnoses for conditions like hypertension and diabetes, as well as specific types of health support classifications.
RIZAP stated that after inquiring with the AI service provider, they determined the data was likely not used for model training, as files containing personally identifiable information or those deleted within 24 hours are typically excluded from training processes. However, the company is still investigating whether employees of the AI service provider could have accessed the information.
RIZAP has reported the incident to the Personal Information Protection Commission and is coordinating with relevant organizations to notify affected individuals. To prevent recurrence, the company plans to reinforce bans on unauthorized AI services and is considering the implementation of an AI Management System (AIMS) alongside its existing Information Security Management System (ISMS).