University of Miami Data Breach
University of Miami Email Breach Affects 973 Individuals
What happened in the University of Miami data breach?
The University of Miami data breach was reported on December 22, 2022 and affected 973 individuals. The breach type was Unauthorized Access/Disclosure involving Email. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
University of Miami Breach Details
University of Miami Healthcare Data Breach Report
Incident Overview
The University of Miami, a major academic medical institution located in Miami, Florida, experienced an unauthorized access incident involving its email systems in late 2022. The breach resulted in the exposure of protected health information (PHI) belonging to approximately 973 individuals. The breach was formally reported to the U.S. Department of Health and Human Services Office for Civil Rights on December 22, 2022, indicating that the institution discovered and investigated the unauthorized access to email accounts containing sensitive patient and employee health information. This incident represents a significant security event for the institution's healthcare operations and affected patients who had entrusted their medical information to the university's care.
Discovery and Response Timeline
The University of Miami identified the unauthorized access to its email systems through its security monitoring and incident response procedures. Upon discovery, the institution initiated a comprehensive investigation to determine the scope of the breach, identify which individuals were affected, and assess what specific information may have been accessed or disclosed. The institution worked to secure affected email accounts, implement remedial measures to prevent further unauthorized access, and prepare notifications for affected individuals as required under the Health Insurance Portability and Accountability Act (HIPAA). The submission date of December 22, 2022, indicates the institution met its obligation to report the breach to HHS within 60 days of discovery, as mandated by HIPAA Breach Notification Rule requirements.
Technical Details of the Breach
The breach occurred through unauthorized access to email systems, which typically indicates either compromised credentials, exploitation of email server vulnerabilities, or successful phishing attacks that allowed threat actors to gain access to legitimate user accounts. Email systems are particularly valuable targets for healthcare data breaches because they often contain unstructured data including patient communications, medical records, appointment information, billing details, and other sensitive health information that may not be encrypted or subject to the same access controls as dedicated electronic health record (EHR) systems. The fact that no business associate was involved suggests this was a direct compromise of the University of Miami's own infrastructure rather than a third-party vendor incident. Email-based breaches typically allow attackers extended access periods before detection, as email accounts can be monitored for sensitive information over time, and forwarding rules can be established to exfiltrate data without triggering immediate alerts.
Organizational Context
The University of Miami is a private research university with a significant healthcare presence in South Florida, operating through its Miller School of Medicine and affiliated healthcare facilities. The institution provides clinical services, conducts medical research, and trains healthcare professionals, making it a repository for substantial amounts of patient health information. As an academic medical center, the University of Miami maintains electronic health records for patients seen at its clinics, hospitals, and specialty care centers throughout the Miami-Dade County region and beyond. The institution's size and complexity, combined with its role as a teaching hospital and research facility, means it manages health information for thousands of patients and maintains extensive email communications related to patient care, clinical research, and healthcare operations.
Impact on Affected Individuals
Approximately 973 individuals were affected by this breach, representing patients and potentially employees whose health information was accessible through compromised email accounts. The individuals affected may have included patients who received care at University of Miami healthcare facilities, research study participants, and possibly healthcare workers whose employment health records were stored in email systems. These individuals were notified of the breach in accordance with HIPAA requirements, which mandate that covered entities notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach. The notification process would have included information about the nature of the breach, the types of information exposed, steps the institution was taking to address the incident, and recommendations for individuals to monitor their personal information and credit reports for signs of misuse.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, healthcare organizations must notify affected individuals, the media (if more than 500 residents of a state are affected), and the HHS Secretary of any breach of unsecured PHI. Email-based breaches represent a significant category of healthcare data incidents, accounting for a substantial portion of reported breaches in the healthcare sector. These incidents often result from human factors such as credential compromise through phishing, weak password practices, or accidental misconfiguration of email forwarding and sharing settings. The University of Miami's breach falls within the medium severity range due to the number of affected individuals and the typical sensitivity of health information accessible through email systems. Healthcare organizations have increasingly implemented email security controls including multi-factor authentication, advanced threat protection, data loss prevention tools, and employee security awareness training to mitigate the risk of email-based breaches. The fact that this breach was discovered and reported demonstrates the institution's compliance with HIPAA's breach detection and notification requirements, though it also highlights the ongoing vulnerability of email systems as a vector for healthcare data exposure.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the University of Miami Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized healthcare services, and contact your healthcare providers immediately if you identify suspicious activity
Change passwords for email accounts and any online healthcare portals, using strong, unique passwords; enable multi-factor authentication where available to prevent unauthorized account access
Be vigilant against phishing emails and social engineering attempts; verify requests for personal or health information by contacting organizations directly using known phone numbers or websites rather than information provided in unsolicited communications
Consider enrolling in identity theft protection or credit monitoring services if offered by the University of Miami or available through your insurance; document all communications related to the breach for your records
Contact the University of Miami's breach notification team or your healthcare provider if you have questions about what information was exposed or need guidance on protective measures
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida
Technical Notes
University of Miami Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for University of Miami