University of South Florida, USF Health Care
Disclosed Dec 11, 20178 years ago1,279 affectedConfirmed
University of South Florida Health, the covered entity (CE), reported that participants in a clinical trial coordinated by its TrialNet Coordination Center received the protected health information (PHI) of other participants. The breach affected 1,279 individuals. The misdirected PHI included patients’ names, names of patients’ family members, family medical histories, and mailing addresses. The CE provided breach notification to HHS and the affected individuals. Media notification was not required, as less than 500 individuals in a single geographic region were affected by the breach. Following the breach, the CE adopted and implemented a new procedure for printing and mailing documents containing PHI. The CE provided HIPAA training to all staff members in its TrialNet Coordination Center and implemented a process to inform supervisors when workforce members’ annual HIPAA training is due. The CE also sanctioned the employees responsible for the breach and for ensuring the responsible employee received HIPAA training. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 1,279 (as reported to HHS) |
|---|---|
| Disclosed | Dec 11, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): University of South Florida, USF Health Care (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 11, 2017 | 1,279 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about University of South Florida, USF Health Care