Central Florida Inpatient Medicine
Disclosed Jun 7, 20224 years ago19,625 affectedConfirmed
The covered entity (CE), Central Florida Inpatient Medicine, reported that an employee was the victim of an email phishing attack that affected the protected health information (PHI) of 19,625 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, drivers’ license numbers, diagnoses, lab results, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice its website. In its mitigation efforts, the CE offered complimentary credit monitoring services and strengthened it administrative and technical safeguards. The CE also retrained its employees on email security. OCR provided the CE with technical assistance regarding the HIPAA Breach Notification Rule.
What is known
| People affected | 19,625 (as reported to HHS) |
|---|---|
| Disclosed | Jun 7, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Central Florida Inpatient Medicine (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 7, 2022 | 19,625 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.