Palmetto Operating LLC d/b/a Palmetto Subacute Care Center (‘Palmetto’) Data Breach
Palmetto Subacute Care Center EMR Breach Affects 2,746
What happened in the Palmetto Operating LLC d/b/a Palmetto Subacute Care Center (‘Palmetto’) data breach?
The Palmetto Operating LLC d/b/a Palmetto Subacute Care Center (‘Palmetto’) data breach was reported on February 26, 2025 and affected 2,746 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Palmetto Operating LLC d/b/a Palmetto Subacute Care Center (‘Palmetto’) Breach Details
Palmetto Operating LLC Data Breach Report
Incident Overview
Palmetto Operating LLC, operating as Palmetto Subacute Care Center, a skilled nursing and subacute care facility located in Florida, experienced an unauthorized access incident involving its Electronic Medical Record (EMR) system. The breach was reported to the U.S. Department of Health and Human Services on February 26, 2025, affecting 2,746 individuals. The unauthorized access to the EMR system represents a significant compromise of patient privacy, as electronic medical records typically contain comprehensive health information spanning diagnoses, treatment plans, medication histories, and other sensitive clinical data.
Discovery and Response Timeline
While specific discovery dates are not detailed in the breach submission, Palmetto's notification to HHS on February 26, 2025, indicates the organization identified and reported the incident within the required HIPAA notification timeframe of 60 days from discovery. The involvement of a Business Associate in this breach suggests the unauthorized access may have occurred through a third-party vendor or service provider with access to Palmetto's systems. Organizations are required under HIPAA Breach Notification Rule to conduct a thorough investigation, determine the scope of the breach, and notify affected individuals without unreasonable delay. Palmetto's submission indicates the organization completed its investigation and determined that 2,746 individuals required notification of potential exposure.
Technical Details and Breach Mechanism
The breach involved unauthorized access to an Electronic Medical Record system, which typically means an actor gained entry to Palmetto's digital health information infrastructure without authorization. EMR systems are centralized repositories containing patient medical histories, clinical notes, test results, imaging reports, and treatment documentation. Unauthorized access to such systems may occur through various vectors including compromised credentials, exploitation of software vulnerabilities, inadequate access controls, or insider threats. The fact that a Business Associate was involved suggests the breach may have originated from or been facilitated through a third-party vendor's systems or network connection. Business Associates—entities that handle PHI on behalf of covered entities—are required to maintain equivalent security standards under HIPAA, and breaches involving their systems often indicate gaps in vendor management, access controls, or security monitoring.
Organizational Context
Palmetto Subacute Care Center operates as a skilled nursing facility and subacute care provider in Florida, serving patients requiring post-acute care, rehabilitation, and specialized medical services. Subacute care facilities typically serve patients transitioning from acute hospital settings who require ongoing medical management but not the intensive services of a hospital. These facilities maintain comprehensive electronic health records for each patient, including detailed clinical information, medication administration records, and care plans. The facility's use of an EMR system indicates a modern healthcare infrastructure, though the breach suggests potential gaps in access controls, system monitoring, or vendor security management. The involvement of a Business Associate in the breach underscores the complexity of healthcare data ecosystems, where patient information flows through multiple vendors and service providers.
Patient Impact and Notification
Approximately 2,746 patients or individuals associated with Palmetto Subacute Care Center had their protected health information potentially exposed through the unauthorized EMR access. These individuals likely include current and former patients whose medical records were stored in the compromised system. The notification process, required under HIPAA's Breach Notification Rule, must include specific information: a description of the breach, the types of information involved, steps individuals should take to protect themselves, what Palmetto is doing to investigate and prevent future breaches, and contact information for questions. Affected individuals should have received written notification by mail or email, depending on contact information available in Palmetto's records. The 60-day notification requirement means individuals were notified by late April 2025 at the latest, though notification may have occurred sooner depending on when the breach was discovered.
Data Exposure and Privacy Implications
Electronic Medical Records typically contain highly sensitive protected health information including: patient names, dates of birth, medical record numbers, Social Security numbers, insurance information, diagnoses and medical conditions, medication lists and dosages, laboratory and imaging results, treatment plans and clinical notes, provider names and contact information, and billing and payment information. The unauthorized access to this comprehensive health data creates significant privacy risks and potential for misuse. Unlike a breach involving only demographic information, EMR breaches expose detailed clinical data that could be used for identity theft, insurance fraud, medical fraud, or other malicious purposes. The sensitivity of medical information means affected individuals face elevated risks compared to breaches of limited data types.
HIPAA Compliance and Industry Context
Unauthorized access incidents represent one of the most common breach types in healthcare, accounting for a substantial portion of reported breaches annually. The involvement of a Business Associate highlights the importance of HIPAA's Business Associate Agreement requirements, which mandate that third-party vendors maintain equivalent security safeguards. Under the HIPAA Security Rule, covered entities and Business Associates must implement administrative, physical, and technical safeguards including access controls, audit controls, integrity controls, and transmission security. The breach at Palmetto suggests potential deficiencies in one or more of these safeguard categories. Healthcare organizations are required to conduct regular risk assessments, implement appropriate security measures based on identified risks, and maintain comprehensive audit logs to detect unauthorized access. The notification of this breach serves as a reminder to all healthcare organizations of the critical importance of strong access controls, continuous security monitoring, and rigorous vendor management practices.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Palmetto Operating LLC d/b/a Palmetto Subacute Care Center (‘Palmetto’) Breach
Monitor credit reports and financial accounts closely for signs of fraudulent activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized credit applications
Review Explanation of Benefits (EOB) statements from your insurance provider and medical bills for unauthorized charges or services you did not receive; report any suspicious activity to your insurance company and healthcare providers immediately
Contact Palmetto Subacute Care Center and your healthcare providers to verify the accuracy of your medical records and request notification if any unauthorized access or modifications to your records are discovered
Consider enrolling in identity theft protection or credit monitoring services if offered by Palmetto as part of breach remediation; maintain documentation of all breach-related communications and notifications for future reference
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida