Florida Health Sciences Center, Inc Data Breach
Florida Health Sciences Center Paper Records Breach Affects 896
What happened in the Florida Health Sciences Center, Inc data breach?
The Florida Health Sciences Center, Inc data breach was reported on October 3, 2025 and affected 896 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Florida Health Sciences Center, Inc Breach Details
Florida Health Sciences Center Unauthorized Access Incident
On October 3, 2025, Florida Health Sciences Center, Inc. reported a breach of protected health information (PHI) affecting 896 individuals. The breach involved unauthorized access to and disclosure of patient records maintained in paper and film formats. This incident represents a significant privacy violation under the Health Insurance Portability and Accountability Act (HIPAA) and required mandatory notification to affected patients, the Florida Department of Health, and the U.S. Department of Health and Human Services Office for Civil Rights (OCR).
Discovery and Initial Response
The breach was discovered through internal audit procedures and security reviews conducted by Florida Health Sciences Center. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of unauthorized access, identify which patient records were compromised, and establish a timeline of the incident. The entity worked to notify all affected individuals within the timeframe required by HIPAA regulations, which mandates notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The submission date of October 3, 2025, indicates the organization reported the incident to regulatory authorities as required by law.
Breach Mechanism and Operational Impact
The breach involved unauthorized access to paper and film records, which are physical documents and imaging materials stored within the organization's facilities. This type of breach typically occurs through inadequate physical security controls, such as unsecured storage areas, missing or damaged locks, insufficient access restrictions, or failure to implement proper document handling procedures. Unlike digital breaches that may involve sophisticated hacking techniques, paper-based breaches often result from human error, negligence, or deliberate theft of physical materials. The location designation of "Paper/Films" indicates that the compromised information was not stored in electronic systems but rather in traditional physical formats commonly used in healthcare settings for patient charts, imaging records, and historical documentation.
Organizational Context
Florida Health Sciences Center, Inc. is a healthcare provider organization operating in Florida. The organization maintains patient records in multiple formats, including both electronic and physical documentation systems. The presence of paper and film records suggests the organization may operate clinical facilities, diagnostic imaging departments, or maintain historical patient archives. The breach affecting 896 individuals indicates a mid-sized healthcare operation or a specific department or service line within a larger system. The organization's operations likely include direct patient care services, medical record management, and diagnostic services that generate film-based records such as X-rays, CT scans, or other radiological imaging.
Patient Impact and Notification
Approximately 896 patients had their protected health information potentially exposed through unauthorized access. These individuals received breach notification letters informing them of the incident, the types of information compromised, the organization's investigation findings, and recommended protective measures. The notification process is a critical component of HIPAA compliance and serves to inform patients of potential risks to their privacy and security. Affected individuals were provided information about the breach discovery date, the types of PHI involved, steps the organization is taking to prevent future incidents, and resources available to monitor their health and financial information for potential misuse.
HIPAA Compliance and Industry Context
Unauthorized access breaches represent a significant category of healthcare data incidents. According to the U.S. Department of Health and Human Services, unauthorized access and disclosure incidents account for a substantial portion of reported healthcare breaches. Paper-based breaches, while less common than digital breaches in recent years, remain a persistent vulnerability in healthcare organizations that have not fully transitioned to electronic-only record systems. HIPAA requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect PHI. Physical safeguards specifically address the protection of paper records and include requirements for facility access controls, workstation use policies, and workstation security. The breach by Florida Health Sciences Center indicates a potential gap in physical security controls, such as inadequate access restrictions to areas containing patient records, insufficient monitoring of record storage areas, or failure to implement proper document destruction procedures for outdated records.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Florida Health Sciences Center, Inc Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and medical bills carefully for any services or charges you did not authorize or receive. Contact your insurance provider and healthcare providers immediately if you identify suspicious activity.
Monitor your medical records by requesting copies from Florida Health Sciences Center and your other healthcare providers to verify accuracy and identify any unauthorized additions or changes to your medical history.
Consider enrolling in identity theft protection or credit monitoring services, particularly those that include medical identity theft monitoring. Many breach notifications include offers for complimentary monitoring services.
Change passwords for any online healthcare portals, insurance accounts, or other sensitive accounts, and use strong, unique passwords that are not reused across multiple platforms.
Be cautious of unsolicited phone calls, emails, or mail requesting personal or medical information. Verify the identity of callers before providing any information, and report suspicious communications to the appropriate authorities.
Document all communications related to this breach, including notification letters, your responses, and any suspicious activity you discover. Keep records for at least three years.
Contact the Florida Department of Health or the Federal Trade Commission (FTC) to report any identity theft or fraud that occurs as a result of this breach.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida