On September 3, the RIZAP Group apologized after an employee of its subsidiary, RIZAP, mistakenly uploaded personal information and sensitive personal information of customers to an external generative AI service used for personal purposes.

The mistakenly uploaded data consisted of a portion of the target individuals registered in the management system for "Specific Health Guidance" provided by the company between January 1 and August 19.

The information included names, dates of birth, gender, health insurance certificate symbols and numbers, and email addresses, as well as some addresses and phone numbers. Additionally, sensitive personal information, such as medical data regarding hypertension and diabetes, was included.

The incident occurred during data aggregation. Immediately following the discovery, the company deleted the chat history and configured the settings to disable the use of data for training.

Following an inquiry to the AI service provider, the company determined that the files were unlikely to have been used for model training, as they were deleted within 24 hours of the upload.

The company is currently verifying whether the service provider's officers or employees were in a position to view the information. It stated that it will provide individual notifications to the affected business partners and customers as soon as confirmation is complete.

As measures to prevent recurrence, the company stated that it will notify employees of the prohibition of using unauthorized generative AI for business purposes and is considering the introduction of an AI Management System (AIMS).


Source: RIZAP社員、私用AIに顧客の個人情報入力 氏名や疾患、保険証番号など……同社が謝罪 (ITmedia AI+, 2026-09-04)