← Incident database

rizap-ai-data-handling-2026 · Disclosed 2026-09-02

IHIグループ健康保険組合: data exposure and authorization boundaries

A RIZAP employee submitted health-guidance data to generative AI during extraction; this is not evidence of attacker AI use. The IHI fund identified 210 affected members and reports that the AI provider ruled out access by other parties and training use.

Supply chain / CIConfiguration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    A RIZAP employee submitted health-guidance data to generative AI during extraction; this is not evidence of attacker AI use.

    [s1]2026/09/02 本文
  • Reported fact

    The IHI fund identified 210 affected members and reports that the AI provider ruled out access by other parties and training use.

    [s1]2026/09/02 本文

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Affected members are being notified and vendor data-handling procedures reviewed.

    [s1]2026/09/02 本文

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The employer’s external-model submission is not evidence of attacker AI use. The reviewed health-insurance disclosure covers 210 people, not the whole RIZAP event.

Sources

  1. [s1] IHIグループ健康保険組合 · Primary source

    IHIグループ健康保険組合:事故に関する公表資料 ↗

    Reviewed 2026-10-09