Moffitt Cancer Center and Research Institute
ent_bbea6aabfb11ab63341f0e28
Disclosures
6
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
95,695
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Moffitt Cancer Center and Research Institute
- Normalized
- moffitt cancer center and research institute— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- moffitt.org
Disclosure history (6)newest first
- FLHHS OCRas victim2024-05-24
Moffitt Cancer Center and Research Institute reported to HHS on 2024-05-24 a Unauthorized Access/Disclosure affecting 756 individuals. Breached information located on Other. An employee emailed PHI (names, treatment info, dates of service, health insurance) to a personal account. The CE notified HHS, individuals, and media, sanctioned the employee, and retrained staff.
- 🦞Maine State AGas victim2024-04-24
Moffitt Cancer Center and Research Institute reported a data breach impacting 24 Maine residents after a third-party vendor experienced a security incident. The breach occurred between October 25, 2023, and October 26, 2023, and was discovered on February 21, 2024. The compromised information includes names and Social Security Numbers. Affected individuals were notified on April 23, 2024, and offered 24 months of credit monitoring and identity theft protection services through Kroll.
- FLHHS OCRas victim2024-04-24
Moffitt Cancer Center and Research Institute (FL) reported to HHS on 2024-04-24 a Hacking/IT Incident affecting 26,577 individuals. The covered entity's business associate experienced a cybersecurity incident that exposed PHI including names, Social Security numbers, dates of birth, claims information, diagnoses, and medications. Breached information located on Network Server. The CE and BA provided credit monitoring; the BA implemented additional administrative, technical, and security safeguards.
- 🍁Vermont State AGas victim2024-04-23
Advarra, Inc, a third-party service provider for Moffitt Cancer Center, notified consumers of a data breach occurring on October 25, 2023. An unauthorized third party accessed a single employee account, compromising names. Advarra disabled the account, engaged cybersecurity experts, and provided 24 months of free identity monitoring via Kroll. The incident is contained.
- FLHHS OCRas victim2020-10-20
Moffitt Cancer Center reported to HHS on 2020-10-20 a Hacking/IT Incident affecting 95695 individuals. Breached information located on Network Server. The incident involved a business associate cyber-attack exposing ePHI including names, DOB, addresses, SSNs, financial, and treatment data. The CE notified HHS, individuals, media, and posted a substitute notice.
- FLHHS OCRas victim2020-09-02
H. Lee Moffitt Cancer Center & Research Institute reported to HHS on 2020-09-02 a Theft affecting 4056 individuals. Breached information located on Other Portable Electronic Device, Paper/Films. A briefcase containing electronic storage devices and documents was stolen from an employee's vehicle. PHI involved included names, dates of birth, and treatment information.