Florida Department of Health
bd_51f19f940f5c5865 · schema v1 · pii pii-v1
Full breach record for Florida Department of Health →Florida Department of Health reported to HHS on 2013-12-23 an Unauthorized Access/Disclosure affecting 2,354 individuals. OCDOH employees with authorized access to the CE's Health Maintenance System (HMS) photographed computer screens containing PHI with smartphones and provided the data to a third party for fraudulent tax return filing. PHI exposed included patient names, dates of birth, and Social Security numbers. Breached information located on Desktop Computer. The CE sanctioned the employees, masked SSNs system-wide, updated access policies, and completed staff training. OCR obtained assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 23, 2013
- Raw hash
- b3a741353f1cdf0f4f5667b189591683fe034d6e73dfa2d72be6fa86cb494d9c
Source filing
Reporting entity
- Name
- Florida Department of Healthnorm: florida department of health
- Domain
- floridahealth.gov
- Industry
- Health Care Services
Victim entity
- Name
- Florida Department of Healthnorm: florida department of health
- Domain
- floridahealth.gov
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Oct 30, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,354
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1052 Exfiltration Over Physical Medium
- Threat actor
- InternalFinancial
- Regulator citations
- HHS OCR notifiedOCR obtained assurances that corrective actions were implemented
- Initial access
- insider_action
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 30, 2013→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.