AdventHealth Daytona Beach Data Breach
AdventHealth Daytona Beach: 821 Patients Affected by Paper Records Loss
What happened in the AdventHealth Daytona Beach data breach?
The AdventHealth Daytona Beach data breach was reported on January 20, 2026 and affected 821 individuals. The breach type was Loss involving Paper/Films. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
AdventHealth Daytona Beach Breach Details
AdventHealth Daytona Beach Data Breach Report
Incident Overview
AdventHealth Daytona Beach, a healthcare facility located in Volusia County, Florida, reported a data breach affecting 821 individuals on January 20, 2026. The breach involved the loss of paper medical records and films, representing a physical security incident rather than a cyber-based attack. The loss of these tangible healthcare documents exposed patients' protected health information (PHI) to potential unauthorized access, as the physical materials were no longer under the organization's direct control or security protocols.
Discovery and Response Timeline
The breach was discovered through AdventHealth Daytona Beach's internal inventory and audit procedures, which identified that paper records and associated films were missing from secure storage locations. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the loss, identify which patient records were affected, and assess the sensitivity of the exposed information. The entity submitted notification of the breach to the U.S. Department of Health and Human Services (HHS) on January 20, 2026, meeting the HIPAA Breach Notification Rule requirement to report breaches affecting 500 or more residents of a state or jurisdiction to the media and HHS. AdventHealth Daytona Beach subsequently notified affected patients in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Breach Mechanism and Specific Details
The breach involved the physical loss of paper medical records and radiographic films, which are common components of patient medical files in healthcare settings. Paper-based records and films are particularly vulnerable to loss through misplacement, theft, or inadequate physical security controls. Unlike digital breaches that may involve sophisticated hacking techniques, physical record losses typically occur due to factors such as improper storage procedures, inadequate access controls, insufficient inventory management, or human error in document handling and archival processes. The loss of films—which typically include X-rays, CT scans, and other diagnostic imaging—represents a significant exposure of sensitive clinical information that could reveal detailed information about a patient's medical conditions, treatments, and health status.
Organizational Context
AdventHealth Daytona Beach is part of the AdventHealth system, a large, multi-state healthcare network operated by Adventist Health System. The Daytona Beach facility serves the central Florida region, providing acute care services, emergency department care, surgical services, and various specialty medical services to the surrounding community. As a hospital facility, AdventHealth Daytona Beach maintains extensive paper-based documentation systems alongside electronic health records (EHRs), as many healthcare organizations continue to use hybrid record-keeping systems. The organization is subject to HIPAA Privacy, Security, and Breach Notification Rules, which establish minimum standards for protecting patient health information and require notification when breaches occur.
Patient Impact and Notification
A total of 821 individuals were affected by this breach, representing patients whose medical records and diagnostic films were lost. These patients received notification letters from AdventHealth Daytona Beach detailing the nature of the breach, the types of information potentially exposed, and recommended steps to protect themselves. The notification process, required under HIPAA regulations, included information about the breach discovery date, a description of the types of PHI involved, steps patients should take to protect themselves, and information about the organization's response to the incident. Affected patients were advised to monitor their medical records for accuracy and to remain vigilant for potential misuse of their health information.
Data Exposure and Risk Assessment
The loss of paper medical records and films likely exposed multiple categories of protected health information, including patient names, dates of birth, medical record numbers, insurance information, diagnoses, treatment plans, medication lists, and detailed clinical notes. The radiographic films and associated diagnostic imaging records contained highly sensitive clinical information revealing specific medical conditions and treatment histories. Depending on the records involved, patients' Social Security numbers, financial information, or emergency contact details may also have been included in the lost documents. The sensitivity of this information is substantial, as medical records contain some of the most personal and confidential information individuals possess, with potential implications for privacy, discrimination, and identity theft if misused.
Industry Context and HIPAA Implications
Physical loss of medical records remains a significant source of healthcare data breaches, accounting for a notable percentage of reported incidents annually. The HIPAA Breach Notification Rule defines a breach as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of such information. While the loss of records does not necessarily prove that unauthorized access occurred, HIPAA regulations presume that loss creates a reasonable risk of compromise unless the organization can demonstrate that the information was destroyed or rendered unusable before loss. Healthcare organizations are required to implement administrative, physical, and technical safeguards to protect patient information, including secure storage of paper records, restricted access controls, regular inventory audits, and documented procedures for record handling and destruction. The loss of 821 patient records at a single facility underscores the importance of strong physical security measures and inventory management systems in healthcare settings.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the AdventHealth Daytona Beach Breach
Monitor your medical records for accuracy and contact AdventHealth Daytona Beach or your healthcare providers if you notice any unauthorized entries, treatments, or charges
Review your health insurance statements and explanation of benefits (EOB) documents for any unauthorized claims or services you did not receive
Consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) and monitor your credit reports for suspicious activity
If you believe your information has been misused, file a report with the Federal Trade Commission (FTC) at IdentityTheft.gov and consider filing a police report with local law enforcement
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida