Agency for Health Care Administration
Disclosed Jan 5, 20188 years ago30,000 affectedConfirmed
On November 20, 2017, the Agency for Health Care Administration, the covered entity (“CE”), discovered that one of its employees had been the victim of a phishing incident, potentially exposing the names, dates of birth, addresses, social security numbers, clinical and health insurance information of 29,641 individuals. The CE provided timely breach notification to HHS, to the affected individuals and to the media. At the time of the breach and currently, the CE trained its employees on its HIPAA policies and procedures and including the reporting of suspicious emails. In response to the breach, the CE retrained the employee at fault and its entire workforce on identifying and reporting potential phishing emails. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 30,000 (as reported to HHS) |
|---|---|
| Disclosed | Jan 5, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Agency for Health Care Administration (Health Plan, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 5, 2018 | 30,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.