- State
- FL
- Covered entity type
- Health Plan
- Individuals affected
- 2,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
For a period of approximately 24 hours on July 25 and 26, 2017, an unauthorized individual was able to access an email account belonging to an employee of the covered entity, Florida Healthy Kids Corporation, via a successful phishing attack. The employee received the email on July 25, 2017, correctly identified it as suspicious, and contacted the CE’s information technology (IT) department. Following the IT department’s instructions, the employee opened an attachment to the email and entered her username and password, allowing the phishing program to access her email account. The CE determined that approximately 2,000 individuals were affected, and that the protected health information (PHI) involved included names, addresses, email addresses, dates of birth, phone numbers, social security numbers, member account numbers, immigration cards, health bills, medical claims information, and income verification documents. In response to this incident and OCR’s investigation, the CE conducted a complete review of its IT systems, and implemented additional security measures including improved auditing procedures and two-factor identification. The CE provided additional training related to phishing scams and terminated the IT department employee involved in this incident. The CE provided breach notification to HHS, affected individuals, the media, and on its website. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.