Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) Data Breach
Treasure Coast Hospice Email Breach Affects 13,230 Patients
What happened in the Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) data breach?
The Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) data breach was reported on September 19, 2025 and affected 13,230 individuals. The breach type was Unauthorized Access/Disclosure involving Email. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) Breach Details
Treasure Coast Hospice Data Breach Report
Incident Overview
Health & Palliative Services of the Treasure Coast, Inc, operating as Treasure Coast Hospice, experienced an unauthorized access incident involving its email systems that compromised the personal health information of 13,230 individuals. The breach was discovered and reported to the Florida Department of Health on September 19, 2025. The incident represents a significant unauthorized disclosure event affecting a substantial patient population across the organization's service area in Florida's Treasure Coast region. Email systems are frequently targeted in healthcare breaches due to their widespread use for clinical communications, appointment scheduling, and administrative functions that may contain sensitive patient data.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in available breach notification records. However, Treasure Coast Hospice's submission to state authorities on September 19, 2025, indicates the organization completed its investigation and determined notification was required under Florida's breach notification law and HIPAA Breach Notification Rule. The organization likely conducted a forensic investigation to determine the scope of unauthorized access, identify which patient records were compromised, and assess the sensitivity of exposed information. Standard HIPAA requirements mandate that covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information.
Technical Details of the Email Breach
Unauthorized access to email systems typically occurs through several common vectors: compromised user credentials (phishing, password reuse, weak passwords), unpatched email server vulnerabilities, misconfigured email security settings, or insider threats. Email breaches are particularly concerning in healthcare because email inboxes often contain clinical notes, patient communications, appointment details, insurance information, and other sensitive protected health information (PHI). Unlike database breaches where attackers may access structured records, email breaches can expose a wide variety of data types depending on what communications were stored in affected mailboxes. The scope of exposure depends on which email accounts were compromised, how long unauthorized access persisted, and what patient information was contained in those accounts. Email-based breaches often affect multiple data types simultaneously, as clinical staff may discuss patient cases, share test results, or communicate insurance details through email.
Organizational Context
Treasure Coast Hospice is a healthcare organization providing palliative and hospice care services in Florida's Treasure Coast region, which includes Martin, St. Lucie, and Indian River counties. Hospice organizations provide end-of-life care, pain management, and supportive services to terminally ill patients and their families. As a healthcare provider, Treasure Coast Hospice is a HIPAA-covered entity responsible for protecting patient privacy and maintaining the security of electronic protected health information (ePHI). The organization's patient population likely includes elderly individuals, cancer patients, and others with serious illnesses—populations particularly vulnerable to identity theft and fraud. The breach affected 13,230 individuals, indicating a substantial patient base and suggesting the organization operates multiple care locations or has served a large cumulative patient population.
Patient Population and Data Exposure
The 13,230 affected individuals represent current and potentially former patients of Treasure Coast Hospice who had information stored in the compromised email systems. Patients of hospice organizations are typically elderly, medically fragile, and may have limited ability to monitor their credit or respond to identity theft. The specific data elements exposed likely include names, addresses, dates of birth, medical record numbers, insurance information, and clinical details related to their hospice care. Depending on the email accounts compromised, exposed information may also include Social Security numbers, Medicare/Medicaid numbers, diagnoses, medication lists, and other sensitive health information. Email breaches in healthcare settings frequently expose multiple categories of PHI simultaneously, as clinical staff use email for various administrative and clinical purposes. Notification to affected individuals was required under HIPAA's Breach Notification Rule, which mandates that covered entities inform individuals of breaches involving unsecured PHI without unreasonable delay.
HIPAA Compliance and Industry Context
This incident highlights ongoing vulnerabilities in healthcare email security despite HIPAA's Security Rule requirements for administrative, physical, and technical safeguards. Email remains a critical vulnerability in healthcare cybersecurity, with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) consistently identifying email-based breaches among the most common causes of healthcare data breaches. Healthcare organizations are required to implement access controls, encryption, audit controls, and integrity controls to protect ePHI. Email breaches often result from gaps between policy and implementation—while many organizations have email security policies, enforcement and employee training remain inconsistent. The 13,230-person impact places this breach in the regional significance category, comparable to other multi-facility healthcare breaches affecting mid-sized patient populations. Patients affected by email breaches should be aware that their information may be used for identity theft, fraudulent insurance claims, or targeted phishing attacks, as healthcare data is particularly valuable on the dark web due to its comprehensiveness and long-term utility for fraud.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) Breach
Monitor credit reports from all three major bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements from your insurance provider and medical bills for unauthorized claims or services you did not receive. Contact your insurance company immediately if you identify fraudulent activity.
Monitor your Medicare or Medicaid accounts (if applicable) through your online portals for unauthorized claims, and set up account alerts if available through your insurance provider.
Be cautious of unsolicited phone calls, emails, or mail claiming to be from healthcare providers, insurance companies, or billing services. Verify any requests for personal information by calling the organization directly using a phone number from an official bill or website.
Consider enrolling in credit monitoring or identity theft protection services, particularly if Social Security numbers or financial information was exposed. Many breached organizations offer free credit monitoring for affected individuals.
Update passwords for any online healthcare accounts and use strong, unique passwords. Enable multi-factor authentication where available on healthcare portals and financial accounts.
Request a copy of your medical records from Treasure Coast Hospice to verify accuracy and ensure no unauthorized services or medications were added to your record.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you discover evidence of identity theft or fraud, and keep documentation of all fraudulent activity for potential insurance claims or legal action.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida