AdventHealth
ent_f57151e2b4a5d2d736c8d0e6
Disclosures
5
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
315,337
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AdventHealth
- Normalized
- adventhealth— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- adventhealth.com
Disclosure history (5)newest first
- FLORIDAHHS OCRas victim2026-01-20
AdventHealth Daytona Beach (FL) reported to HHS OCR on 2026-01-20 a Loss affecting 821 individuals. Breached information was located on Paper/Films. No business associate was identified as present.
- FLORIDAHHS OCRas victim2020-10-20
AdventHealth (FL) reported to HHS on 2020-10-20 that its business associate experienced a ransomware attack affecting the ePHI of 315,337 individuals. Breached information was located on a Network Server. Exposed data included names, mailing and email addresses, telephone numbers, dates of birth, financial information, gender, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice.
- Massachusetts State AGas victim2019-01-25
AdventHealth Medical Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-01-25. 29 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-01-25
AdventHealth Medical Group notified Montana residents of a data breach where an unauthorized third party accessed systems at a pulmonary clinic starting August 2017. Discovered Dec 27, 2018. Exposed PHI, SSNs, and PII. Kroll engaged for credit monitoring.
- Illinois State AGas victim2019-01-01
ADVENTHEALTH MEDICAL GROUP filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-011). The register records the breach as discovered on December 17, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.