- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,782
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of the covered entity (CE) sent a group email to current and former patients inviting them to a cancer awareness event and mistakenly failed to mask the recipients' email addresses. This breach affected the protected health information (PHI) of 1,782 individuals by exposing names and an implicit indication that they may have received cancer treatment. The CE recalled the email and immediately investigated the breach. The CE provided breach notification to HHS, affected patients, and the media, and posted substituted notice on its website. The CE established a call center to answer questions for its patients. The CE counseled the involved employee, and the employee’s supervisor reinforced to all department employees instructions regarding the use of group emails and the importance of keeping patients’ emails confidential. The CE reviewed and revised its privacy program in March 2015 and September 2015, which included guidelines for security of electronic PHI/email. In addition, the CE confirmed that it uses an encryption program to ensure the security and integrity of data. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.