Florida Department of Health
ent_147fc51f6aa48ba583243bae
Disclosures
5
HHS OCR · Leak Site · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
729,699
as filed · HHS OCR FL
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Florida Department of Health
- Normalized
- florida department of health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- floridahealth.gov
Disclosure history (5)newest first
- FLHHS OCRas victim2024-08-23
Florida Department of Health reported to HHS on 2024-08-23 a Hacking/IT Incident affecting 729,699 individuals. Breached information was located on a Network Server. PHI involved included names, addresses, dates of birth, diagnoses, conditions, claims information, and Social Security numbers. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. Additional administrative, technical, and security safeguards were implemented in response.
- GLOBALLeak Siteas victim2024-07-03
- GLOBALLeak Siteas victim2024-06-28
- FLHHS OCRas victim2014-12-08
Florida Department of Health (FL) reported to HHS on 2014-12-08 a breach categorized as 'Other' affecting 2,477 individuals. A workforce member sent an unencrypted email with an attachment containing ePHI — including dates of birth, Social Security numbers, screening test results, and diagnoses — to four physicians (the intended recipients). Breached information was located in Email. The CE confirmed deletion of the emails and conducted staff retraining. OCR reviewed the CE's policies and training documentation.
- FLHHS OCRas victim2013-12-23
Florida Department of Health reported to HHS on 2013-12-23 an Unauthorized Access/Disclosure affecting 2,354 individuals. OCDOH employees with authorized access to the CE's Health Maintenance System (HMS) photographed computer screens containing PHI with smartphones and provided the data to a third party for fraudulent tax return filing. PHI exposed included patient names, dates of birth, and Social Security numbers. Breached information located on Desktop Computer. The CE sanctioned the employees, masked SSNs system-wide, updated access policies, and completed staff training. OCR obtained assurances of corrective action.