Edward C. Taylor, PhD., PL Data Breach
Edward C. Taylor Psychology Practice Suffers Hacking Incident
What happened in the Edward C. Taylor, PhD., PL data breach?
The Edward C. Taylor, PhD., PL data breach was reported on October 25, 2023 and affected 6,684 individuals. The breach type was Hacking/IT Incident involving Desktop Computer, Network Server. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Edward C. Taylor, PhD., PL Breach Details
Breach Overview
Edward C. Taylor, PhD., PL, a psychology practice based in Florida, reported a significant hacking and IT security incident to the U.S. Department of Health and Human Services on October 25, 2023. The breach affected the practice's desktop computer and network server infrastructure, potentially compromising the protected health information (PHI) of 6,684 patients. As a mental health provider, the practice maintains particularly sensitive information including psychological evaluations, treatment notes, and mental health diagnoses that may have been accessed by unauthorized parties during this cybersecurity incident.
Company Response and Investigation
Following the discovery of unauthorized access to their computer systems, Edward C. Taylor, PhD., PL initiated an investigation to determine the scope and nature of the security incident. The practice worked to identify which systems were compromised and what patient information may have been accessible to the unauthorized actors. According to the breach report submitted to federal regulators, the incident involved both desktop computers and network servers, suggesting a potentially sophisticated attack that penetrated multiple layers of the practice's IT infrastructure. The practice was required under HIPAA regulations to notify affected patients and report the breach to the Department of Health and Human Services within 60 days of discovery, with the submission occurring in late October 2023.
Specific Technical Details
The breach was classified as a hacking/IT incident affecting both desktop computers and network servers within the practice's infrastructure. This dual-location compromise indicates that attackers may have gained initial access through one vector—such as phishing emails, compromised credentials, or software vulnerabilities—and then moved laterally through the network to access additional systems. Network server compromises are particularly concerning as these systems typically store centralized patient databases, electronic health records, and backup files containing years of accumulated patient data. Desktop computers in healthcare settings often contain locally stored files, email communications with patients, and access credentials to other systems. The fact that no business associate was involved suggests that the practice managed its own IT infrastructure rather than outsourcing to a third-party vendor, which may have implications for the security resources and expertise available to prevent and respond to such incidents.
Organizational Context
Edward C. Taylor, PhD., PL operates as a professional limited liability psychology practice in Florida, providing mental health services to patients in the community. As a solo practitioner or small practice operating under a professional license structure, the organization likely serves patients seeking psychological counseling, therapy, diagnostic evaluations, and other mental health services. Psychology practices of this size typically maintain detailed clinical notes, treatment plans, psychological test results, and sensitive information about patients' mental health conditions, family situations, and personal histories. The practice's patient base of approximately 6,684 individuals suggests an established practice that has been operating for several years, accumulating substantial patient records over time. Small healthcare practices like this one often face unique cybersecurity challenges, as they may lack the dedicated IT security staff and resources available to larger healthcare systems while still being required to comply with the same HIPAA security standards.
Patient Impact and Notifications
The breach affected 6,684 individuals who received or sought mental health services from Edward C. Taylor, PhD., PL. Given the nature of a psychology practice, the compromised information likely included highly sensitive mental health records that patients shared in confidence during therapeutic relationships. Under HIPAA's Breach Notification Rule, the practice was required to notify all affected individuals by mail within 60 days of discovering the breach, providing details about what information was compromised, what steps the practice has taken in response, and what actions patients can take to protect themselves. The notification timeline, based on the October 25, 2023 submission date, suggests that affected patients would have received their individual notifications around the same time period. For many patients, learning that their mental health information may have been accessed by unauthorized parties can be particularly distressing, given the stigma that still surrounds mental health treatment and the deeply personal nature of therapeutic disclosures.
Personal Information Involved
While the specific data elements compromised were not detailed in the breach report, psychology practice records typically contain extensive protected health information. This likely includes patient names, dates of birth, contact information including addresses and phone numbers, Social Security numbers (often collected for billing and insurance purposes), health insurance information and policy numbers, medical record numbers, and detailed clinical information. The clinical information in mental health records is particularly sensitive and may include psychiatric diagnoses, psychological test results, treatment plans, therapy session notes documenting personal disclosures, medication information for psychotropic drugs, family history and relationship details, substance abuse history, trauma history, and information about work or school functioning. Mental health records often contain more detailed narrative information than other medical records, as therapists document conversations, observations, and clinical impressions in session notes. This makes breaches of mental health provider systems especially concerning from a privacy perspective.
Industry Context and HIPAA Implications
This breach represents a growing trend of cyberattacks targeting small and medium-sized healthcare providers, including mental health practices. According to the Department of Health and Human Services Office for Civil Rights, hacking and IT incidents have become the most common type of healthcare data breach, accounting for the majority of breached records in recent years. Small practices are often viewed as attractive targets by cybercriminals because they may have less sophisticated security defenses than large hospital systems while still maintaining valuable patient data. Mental health records can be particularly valuable on the black market due to their sensitive nature and potential use in extortion schemes. HIPAA requires covered entities like Edward C. Taylor, PhD., PL to implement administrative, physical, and technical safeguards to protect electronic protected health information, including access controls, encryption, audit controls, and regular security risk assessments. When breaches occur, practices must conduct thorough investigations, provide notifications, and often implement additional security measures to prevent future incidents. The involvement of both desktop computers and network servers in this breach suggests potential gaps in network segmentation, access controls, or endpoint protection that allowed attackers to move through the practice's systems.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Edward C. Taylor, PhD., PL Breach
Monitor all financial accounts, credit reports, and explanation of benefits statements from health insurers for suspicious activity. Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to prevent unauthorized accounts from being opened in your name.
Review medical records and insurance statements carefully to ensure no fraudulent medical services or prescriptions have been billed in your name. Contact your health insurance company immediately if you notice any unfamiliar claims or services.
Be extremely cautious of phishing emails, phone calls, or text messages that reference your treatment or personal information, as attackers may use compromised data to make scams appear legitimate. Verify the identity of anyone requesting personal or financial information before responding.
Consider enrolling in identity theft protection or credit monitoring services if offered by the practice. Document all communications regarding the breach and keep records of any time or money spent addressing breach-related issues, as you may be entitled to compensation.
Contact the practice directly to understand exactly what information was compromised in your case and what specific security measures have been implemented to prevent future incidents. Ask about available resources for affected patients.
If you experience anxiety, distress, or concerns about privacy related to this breach, discuss these feelings with your mental health provider or seek support from patient advocacy organizations. Consider whether you need to inform family members or others who may have been mentioned in your clinical records.
File a complaint with the Department of Health and Human Services Office for Civil Rights if you believe your privacy rights were violated due to inadequate security practices, and consider reporting the incident to the Florida Attorney General's office and local law enforcement if you experience identity theft or fraud.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida