Back to the register
Florida Department of Health, Children's Medical Services
ArchivedSubmitted 10/23/2015
- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 500
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Florida Department of Health, Children’s Medical Services, discovered that that an employee faxed an e-mail roster with all patients that needed medical supplies to each of their medical vendors. The policy is that the medical supply vendor only receives the names of patients to whom it will directly supply orthopedic supplies. The protected health information (PHI) on the e-mail roster included patients' names, dates of birth, and the insurance information of 523 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and also posted substitute notice on its website. The CE also set up a toll free telephone number to answer questions. In response to the breach, the CE ceased the practice of sending daily rosters containing patient information to vendors. The CE sanctioned and re-trained the employee involved in this breach and retrained all employees on its HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.