- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 960
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Broward Health Medical Center, the covered entity (CE), discovered that an employee had taken paper patient facesheets off the premises, which were then stolen from the employee’s home by a visitor. The names, dates of birth, addresses, telephone numbers, social security numbers, primary insurance providers, insurance guarantors, reasons for visits, employers, and emergency contact information pertaining to 960 potentially affected individuals was exposed due to the breach. The CE provided breach notification to HHS, to affected individuals and to the media. At the time of the breach the CE had policies in place prohibiting the removal of PHI from the facility and the employee at fault for this incident is no longer employed by the CE. In response to the breach, the CE re-trained its workforce to reinforce its existing policies. OCR provided technical assistance regarding procedures for responding to and reporting privacy incidents as well as the CE’s obligations under the Breach Notification Rule in the event of a law enforcement delay. OCR obtained assurances that the CE has implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.