University of Florida Health
ent_013875dee83b2de53c258d27
Disclosures
3
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
135,959
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Florida Health
- Normalized
- university of florida health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- FLORIDAHHS OCRas victim2020-08-14
University of Florida Health reported to HHS on 2020-08-14 a Hacking/IT Incident affecting 135959 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, DOB, emails, and treatment info.
- New Hampshire State AGas victim2020-08-13
University of Florida Health notified NH AG of a third-party ransomware incident involving vendor Blackbaud. Attack occurred Feb-May 2020. 34 NH residents affected. Data included names, addresses, DOBs, and visit info. Blackbaud paid ransom and confirmed data destruction. UF Health offered 1 year credit monitoring.
- Montana State AGas victim2020-08-12
University of Florida Health notified Montana DOJ of a third-party data breach involving Blackbaud, a service provider hosting UF Health data. Blackbaud suffered a ransomware attack in May 2020, with unauthorized access potentially dating to February 2020. UF Health was notified on July 16, 2020. The incident involved demographic PII (names, addresses, emails, DOBs) but explicitly excluded sensitive data like SSNs, medical records, or financial account numbers. Blackbaud reportedly paid ransom and assured data destruction. UF Health offered 12 months of credit monitoring via ID Experts.
Supply-chain cascadesreviewed and confirmed
- University of Florida Health’s filing is one of at least 172 in the BLACKBAUD, INC. supply-chain incident (2020).