- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,279
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
University of South Florida Health, the covered entity (CE), reported that participants in a clinical trial coordinated by its TrialNet Coordination Center received the protected health information (PHI) of other participants. The breach affected 1,279 individuals. The misdirected PHI included patients’ names, names of patients’ family members, family medical histories, and mailing addresses. The CE provided breach notification to HHS and the affected individuals. Media notification was not required, as less than 500 individuals in a single geographic region were affected by the breach. Following the breach, the CE adopted and implemented a new procedure for printing and mailing documents containing PHI. The CE provided HIPAA training to all staff members in its TrialNet Coordination Center and implemented a process to inform supervisors when workforce members’ annual HIPAA training is due. The CE also sanctioned the employees responsible for the breach and for ensuring the responsible employee received HIPAA training. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.