University of Miami
ent_d48c393031044804
Disclosures
8
HHS OCR · State AG · Leak Site · 3 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
86,000
nationwide · HHS OCR FL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- University of Miami
- Normalized
- university of miami— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493008ZSVWUNRYQE312
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- miami.edu
Disclosure history (8)newest first
- FLHHS OCRas victim2026-06-17
University of Miami reported to HHS on 2026-06-17 a Unauthorized Access/Disclosure affecting 6721 individuals. Breached information located on Electronic Medical Record, Network Server.
- 🦞Maine State AGas victim2023-11-17
The University of Miami reported an inadvertent disclosure of personal information that occurred on June 12, 2017, and was discovered on October 18, 2023. The breach affected one Maine resident, exposing their name and Social Security number. The university offered 24 months of credit monitoring and identity theft protection services from Kroll.
- GLOBALLeak Siteas victim2022-12-22
University of Miami
- FLHHS OCRas victim2022-12-22
University of Miami (FL) reported to HHS on 2022-12-22 an Unauthorized Access/Disclosure affecting 973 individuals. An individual used stolen employee computer credentials to access the network environment containing PHI, including names, dates of birth, diagnoses, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards.
- FLHHS OCRas victim2021-03-23
University of Miami reported to HHS on 2021-03-23 a Hacking/IT Incident affecting 86000 individuals. Breached information located on Network Server. A business associate experienced a cyber-attack compromising PHI including names, addresses, DOB, SSN, and diagnoses. The CE implemented safeguards, provided credit monitoring, and ended the BA relationship.
- FLHHS OCRas victim2014-02-12
University of Miami Health System reported to HHS on 2014-02-12 a Loss affecting 13,074 individuals. On or around June 27, 2013, the CE learned from Iron Mountain (its BA) that 15 boxes of PHI were lost during a transfer between storage/shredding vendors. The boxes contained billing and research records with financial and clinical information. Breached information located on Paper/Films. OCR obtained assurances of corrective actions including retraining, revised procedures, a new HIPAA Privacy Officer, and implementation of the Fair Warning System.
- FLHHS OCRas victim2012-09-07
University of Miami reported to HHS on 2012-09-07 a breach involving the unauthorized printing and sale of patient face sheets by two employees. The incident affected 64,846 individuals, involving demographic and clinical PHI located on paper/films. The breach was discovered by police during an unrelated raid. The entity notified HHS, affected individuals, and the media, applied sanctions to employees, and implemented monitoring and audit log retention programs.
- FLHHS OCRas victim2012-01-30
University of Miami reported to HHS on 2012-01-30 a Theft affecting 1,219 individuals. An unencrypted USB drive was stolen from a pathologist's vehicle; the drive contained ePHI including names, ages, diagnoses, and treatment information. Breached information was located on an Other Portable Electronic Device. The CE notified HHS, patients, and the media; offered credit monitoring; ceased relations with the pathologist (an independent contractor); and retrained personnel on encryption and data protection. OCR obtained assurances that all corrective actions were completed.