Mirra Health Care
Disclosed Dec 8, 20205 years ago1,064 affectedConfirmed
The business associate (BA), Mirra Health Care, reported that an employee had impermissibly provided electronic protected health information (ePHI) to an unauthorized individual via email. This breach affected 1,064 individuals. The ePHI involved included names, addresses, phone numbers, dates of birth, Social Security numbers, and health insurance and clinical information. The BA notified HHS, affected individuals, and the media. In its mitigation efforts, the BA sanctioned the responsible employee and implemented additional administrative, technical, and security safeguards to better protect its PHI. All staff were retrained. OCR provided the BA with technical assistance pertaining to the HIPAA Breach Notification Rule and other obligations.
What is known
| People affected | 1,064 (as reported to HHS) |
|---|---|
| Disclosed | Dec 8, 2020 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mirra Health Care (Business Associate, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 8, 2020 | 1,064 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.