Baptist Medical Center South
Disclosed Jun 30, 20179 years ago531 affectedConfirmed
Baptist Medical South, the covered entity (CE), lost a hard drive that was used to store backup electroencephalogram (EEG) test results. The breach affected 531 individuals and the types of protected health information (PHI) on the drive included patients’ names, dates of birth, hospital and medical record numbers, physicians’ orders, diagnoses, room numbers, and EEG image results. The CE provided breach notification to affected individuals, the media, and HHS and also posted notification on its website. In response to the breach, the CE initiated its security incident procedure, reviewed surveillance video footage, and interviewed employees. The CE also revised its procedures relating to hard drive storage and updated its policies. Additionally, the CE improved physical and technical safeguards, including the use of encryption. The CE also trained its staff on the updated policies and procedures. OCR provided the CE with technical assistance on breach start dates and breach reports. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 531 (as reported to HHS) |
|---|---|
| Disclosed | Jun 30, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Baptist Medical Center South (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 30, 2017 | 531 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.