
RIZAP Group apologized after an employee leaked client data to a personal AI.
The leak included names, medical conditions, and insurance details.
RIZAP says the data was not used for AI training.
What happened
RIZAP Group apologized on September 3 after a subsidiary employee mistakenly uploaded client personal data, including names and medical conditions, to a personal external generative AI service. The company has not disclosed the number of cases.
Why it matters
The leaked data came from RIZAP's specific health guidance system and included sensitive personal information such as insurance card numbers, addresses, phone numbers, and disease details for hypertension and diabetes. This raises serious privacy concerns for clients and business partners.
What to watch
RIZAP says the AI operator confirmed the files were not used for model training, but it is still checking whether the operator's staff could have viewed the data. The company will notify affected clients and partners individually once confirmed.
Ask the AI about this article →
RIZAP Group's apology highlights the risks of employees using personal AI tools for work-related tasks. The company, which provides health guidance services to corporations and health insurance associations, saw a worker upload sensitive client data during a data aggregation task. The leak included names, medical conditions, and insurance details—information that could cause significant harm if misused.
The company says the AI operator confirmed that files containing personally identifiable information are not used for model training, and because the data was deleted within 24 hours, it believes the data was not used for learning. However, RIZAP is still checking whether the operator's staff could have viewed the information. This uncertainty is a key concern for affected clients.
In response, RIZAP is reiterating its ban on using unauthorized generative AI for business, continuing education on data protection, and considering adopting an AI management system alongside its existing information security management system. This incident serves as a reminder that even with safeguards, the human factor remains a critical vulnerability in data security.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Infosys, a founding partner of CrowdStrike's Project QuiltWorks, is bringing enterprise context to CrowdStrike…
Cisco has announced a target to have zero engineers writing code by the end of October
OpenAI's latest model, Astra, can do more thinking off the scratchpad, according to Transformer

Cecilia Ziniti, former general counsel at Replit, left the company in November 2023 and founded GC AI, an AI s…

Governments and companies outside the US and China are building local AI models to avoid relying on foreign sy…

Users report Instagram's "AI Content" label is wrongly appearing on images they edited with tools like Canva's…
