Florida Department of Health, Children's Medical Services
Disclosed Oct 23, 201510 years ago500 affectedConfirmed
The covered entity (CE), Florida Department of Health, Children’s Medical Services, discovered that that an employee faxed an e-mail roster with all patients that needed medical supplies to each of their medical vendors. The policy is that the medical supply vendor only receives the names of patients to whom it will directly supply orthopedic supplies. The protected health information (PHI) on the e-mail roster included patients' names, dates of birth, and the insurance information of 523 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and also posted substitute notice on its website. The CE also set up a toll free telephone number to answer questions. In response to the breach, the CE ceased the practice of sending daily rosters containing patient information to vendors. The CE sanctioned and re-trained the employee involved in this breach and retrained all employees on its HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Oct 23, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Florida Department of Health, Children's Medical Services (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 23, 2015 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Florida Department of Health, Children's Medical Services