- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 531
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Baptist Medical South, the covered entity (CE), lost a hard drive that was used to store backup electroencephalogram (EEG) test results. The breach affected 531 individuals and the types of protected health information (PHI) on the drive included patients’ names, dates of birth, hospital and medical record numbers, physicians’ orders, diagnoses, room numbers, and EEG image results. The CE provided breach notification to affected individuals, the media, and HHS and also posted notification on its website. In response to the breach, the CE initiated its security incident procedure, reviewed surveillance video footage, and interviewed employees. The CE also revised its procedures relating to hard drive storage and updated its policies. Additionally, the CE improved physical and technical safeguards, including the use of encryption. The CE also trained its staff on the updated policies and procedures. OCR provided the CE with technical assistance on breach start dates and breach reports. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.