Barry University
Disclosed Dec 27, 201312 years ago9,017 affectedConfirmed
Barry University, the covered entity (CE), discovered on May 13, 2013, that a laptop was infected with malware. The protected health information (PHI) for 8,741 individuals was potentially exposed, including names, dates of birth, social security numbers, driver’s license numbers, banking/credit card information, medical record numbers, health insurance information, diagnoses, and treatment information. Due to a lengthy investigation, the CE performed its breach notification obligations outside of the 60 day timeframe required by the Breach Notification Rule. OCR provided technical assistance to the CE on this topic. Although late, the CE provided breach notification to HHS, affected individuals, and the media, as well as on its website. In response to the breach, the CE retained a compliance consultant, performed a risk assessment, revised its policies and procedures, improved its training program and implemented additional technical safeguards. OCR obtained assurances that it has implemented the corrective actions listed above.
What is known
| People affected | 9,017 (as reported to HHS) |
|---|---|
| Disclosed | Dec 27, 2013 |
| Happened | May 14, 2013 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Education · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2014 data breach report: Barry Universityin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Barry University (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Dec 27, 2013 | 12 |
| HHS archivetotal | Dec 31, 2013 | 9,017 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 9017 · backfill source
- 2026-09-25 · summary: empty to Barry University, the covered entity (CE), discovered on May 13, 2013, that a laptop was infected with malware. The protected health information (PHI) for 8,741 individuals was potentially exposed, including names, dates of birth, social se · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.