Moffitt Cancer Center and Research Institute
ent_bbea6aabfb11ab63341f0e28
Disclosures
10
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
95,695
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Moffitt Cancer Center and Research Institute
- Normalized
- moffitt cancer center and research institute— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- moffitt.org
Disclosure history (10)newest first
- FLORIDAHHS OCRas victim2024-05-24
Moffitt Cancer Center and Research Institute reported to HHS on 2024-05-24 a Unauthorized Access/Disclosure affecting 756 individuals. Breached information located on Other. An employee emailed PHI (names, treatment info, dates of service, health insurance) to a personal account. The CE notified HHS, individuals, and media, sanctioned the employee, and retrained staff.
- Massachusetts State AGas victim2024-04-25
Moffitt Cancer Center and Research reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-04-25. 44 Massachusetts residents were affected.
- Maine State AGas victim2024-04-24
Moffitt Cancer Center and Research Institute reported a data breach impacting 24 Maine residents after a third-party vendor experienced a security incident. The breach occurred between October 25, 2023, and October 26, 2023, and was discovered on February 21, 2024. The compromised information includes names and Social Security Numbers. Affected individuals were notified on April 23, 2024, and offered 24 months of credit monitoring and identity theft protection services through Kroll.
- Montana State AGas victim2024-04-24
Advarra, Inc, on behalf of Moffitt Cancer Center, notified patients and research participants of a data security incident where an unauthorized third party accessed a single employee account on October 25, 2023. The incident involved names of individuals. Advarra contained the incident on October 26, 2023, engaged cybersecurity experts, and offered 24 months of identity monitoring via Kroll.
- FLORIDAHHS OCRas victim2024-04-24
Moffitt Cancer Center and Research Institute (FL) reported to HHS on 2024-04-24 a Hacking/IT Incident affecting 26,577 individuals. The covered entity's business associate experienced a cybersecurity incident that exposed PHI including names, Social Security numbers, dates of birth, claims information, diagnoses, and medications. Breached information located on Network Server. The CE and BA provided credit monitoring; the BA implemented additional administrative, technical, and security safeguards.
- Vermont State AGas victim2024-04-23
Advarra, a service provider for Moffitt Cancer Center, experienced a data breach on October 25, 2023, when an unauthorized third party accessed a single employee account. The incident was discovered on October 26, 2023. The breach involved the acquisition of limited data, including names of patients and research study participants. Advarra contained the incident, engaged cybersecurity experts, and notified law enforcement. Identity monitoring services were offered to affected individuals.
- Illinois State AGas victim2024-04-01
MOFFITT CANCER CENTER filed a data-breach notice with the Illinois Attorney General in April 2024 (case 24-04-033). The register records the breach as discovered on October 25, 2023. Additional entities named: ADVARRA, INC.. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FLORIDAHHS OCRas victim2020-10-20
Moffitt Cancer Center reported to HHS on 2020-10-20 a Hacking/IT Incident affecting 95695 individuals. Breached information located on Network Server. The incident involved a business associate cyber-attack exposing ePHI including names, DOB, addresses, SSNs, financial, and treatment data. The CE notified HHS, individuals, media, and posted a substitute notice.
- FLORIDAHHS OCRas victim2020-09-02
H. Lee Moffitt Cancer Center & Research Institute reported to HHS on 2020-09-02 a Theft affecting 4056 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. A briefcase containing electronic storage devices and documents was stolen from an employee's vehicle. PHI involved included names, dates of birth, and treatment information.
- Illinois State AGas victim2020-01-01
MOFFITT CANCER CENTER filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-426). The register records the breach as discovered on February 7, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.