FLMisuseHealthcareHealthcarePrivilege AbuseCustomer Data InvolvedData ExfiltratedDelayed DiscoveryPHIHEALTH_BASICIDENTITY_BASICHighResolved
Public Health Trust of Miami-Dade County, Florida
bd_f66ee80739f10e41 · schema v1 · pii pii-v1
Full breach record for Public Health Trust of Miami-Dade County, Florida →Public Health Trust of Miami-Dade County, Florida reported to HHS on 2016-02-19 a Unauthorized Access/Disclosure affecting 24188 individuals. Breached information located on Electronic Medical Record. An employee inappropriately accessed and sold patient PHI since 2011. The system failed to implement minimum necessary access controls and timely breach notification.
HIPAA clockDiscovered Jan 1, 2013 → Notified Feb 19, 20161144d ✗ HIPAA 60-day late38 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed24,188 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 19, 2016
- Raw hash
- 6b60743e0a3cd395c6d8376747ecf3a8fe88085b546caa497d1c117244308f71
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Public Health Trust of Miami-Dade County, Floridanorm: public health trust of miami dade county florida
- Industry
- Health Care Services
Victim entity
- Name
- Public Health Trust of Miami-Dade County, Floridanorm: public health trust of miami dade county florida
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 1, 2013
- Materiality determined
- —
- Notification sent
- Feb 19, 2016
- Affected individuals
- 24,188
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- InternalFinancial
- Regulator citations
- Notified OCR of breachOCR initiated investigation following media reportPaid civil money penalty of $2,154,000
- Initial access
- insider_action
Compliance
- Time to disclose
- 38 months(1144 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 1144dHHS notified · 1144d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 1, 2013→ Notified: Feb 19, 20161144d 60 days HIPAA 60-day late HIPAA Discovered: Jan 1, 2013→ Notified: Feb 19, 20161144d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.