University of Miami Data Breach
University of Miami EMR Breach Affects 2,928 Patients
What happened in the University of Miami data breach?
The University of Miami data breach was reported on July 29, 2025 and affected 2,928 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
University of Miami Breach Details
University of Miami Healthcare Data Breach Report
Incident Overview
On July 29, 2025, the University of Miami reported a significant data breach involving unauthorized access to its Electronic Medical Record (EMR) system. The breach compromised the protected health information (PHI) of approximately 2,928 individuals who received care through University of Miami healthcare facilities. This incident represents a serious violation of patient privacy and triggers mandatory notification requirements under the Health Insurance Portability and Accountability Act (HIPAA). The unauthorized access occurred within the institution's electronic medical record infrastructure, a critical system containing some of the most sensitive patient health information.
Discovery and Response Timeline
The University of Miami discovered the unauthorized access to its EMR system and initiated an immediate investigation to determine the scope and nature of the breach. Upon discovery, the institution took steps to secure the affected systems and prevent further unauthorized access. The organization notified affected individuals as required by HIPAA Breach Notification Rule, which mandates notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. The submission date of July 29, 2025, indicates the breach was reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) within the required timeframe. The University of Miami's response included a comprehensive investigation to identify all affected individuals and the specific data elements that may have been accessed.
Breach Mechanics and Technical Details
The breach involved unauthorized access to the Electronic Medical Record system, which typically houses comprehensive patient health information including clinical notes, test results, medication histories, and treatment plans. EMR systems are frequently targeted by threat actors because they contain consolidated, high-value patient data that can be exploited for identity theft, insurance fraud, or sold on underground markets. The unauthorized access classification suggests that an individual or group gained entry to the system without proper authorization, potentially through compromised credentials, exploitation of system vulnerabilities, or inadequate access controls. Unlike theft or loss incidents, unauthorized access breaches often indicate either an insider threat or external compromise of system security. The fact that no business associate was involved suggests the breach originated from within University of Miami's own infrastructure or systems rather than through a third-party vendor relationship.
Organizational Context
The University of Miami is a major private research university located in Miami, Florida, with significant healthcare operations through its Miller School of Medicine and affiliated clinical facilities. The institution operates multiple healthcare delivery points serving the South Florida region, including hospital facilities, outpatient clinics, and specialty care centers. As an academic medical center, University of Miami provides comprehensive healthcare services ranging from primary care to complex specialty and surgical services. The organization maintains extensive electronic health information systems to support patient care, research, and administrative functions across its healthcare enterprise. The breach's impact on a university-affiliated healthcare system is particularly significant given the institution's role as a major regional healthcare provider and its responsibility to protect patient information across multiple clinical settings.
Patient Impact and Affected Population
Approximately 2,928 individuals were affected by this unauthorized access incident. These patients likely include individuals who received care at University of Miami healthcare facilities during a specific timeframe when the unauthorized access occurred. The affected population may span various patient demographics and clinical specialties served by the institution's healthcare operations. Each affected individual received notification of the breach in accordance with HIPAA requirements, informing them of the unauthorized access, the types of information potentially compromised, and recommended protective measures. The notification process included information about the breach discovery, the University of Miami's response, and guidance on steps patients should take to monitor their health and financial information for potential misuse.
Exposed Protected Health Information
Given the breach location within the Electronic Medical Record system, the following categories of protected health information may have been accessed:
- Patient Demographics: Names, addresses, dates of birth, contact information
- Medical Record Numbers: Unique identifiers used within the healthcare system
- Clinical Information: Medical histories, diagnoses, treatment plans, and clinical notes
- Laboratory and Imaging Results: Test results, imaging reports, and diagnostic findings
- Medication Information: Prescription histories, medication lists, and dosing information
- Insurance Information: Health insurance policy numbers and coverage details
- Social Security Numbers: Potentially included in patient registration records
- Financial Information: Billing records and payment information
- Psychological or Behavioral Health Data: Mental health records if applicable to affected patients
The specific combination of data elements exposed depends on the scope of the unauthorized access and which EMR records were compromised during the incident.
HIPAA Compliance and Regulatory Context
This breach triggers obligations under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), which requires covered entities to notify affected individuals, the media, and the HHS Secretary when unsecured PHI is accessed without authorization. The University of Miami, as a covered entity under HIPAA, must demonstrate that it conducted a thorough risk assessment to determine whether the unauthorized access constitutes a reportable breach. The fact that the breach was reported to HHS OCR indicates that the risk assessment concluded the breach posed a significant risk of harm to affected individuals. Unauthorized access incidents to EMR systems are among the most common breach types reported in healthcare, accounting for a substantial portion of annual breach notifications. These incidents often result from inadequate access controls, insufficient monitoring of system activity, or exploitation of security vulnerabilities.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the University of Miami Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare bills and explanation of benefits statements carefully for unauthorized services or claims; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Monitor your health records for unauthorized access or changes; request copies of your medical records from University of Miami to verify accuracy and identify any unauthorized modifications
Consider enrolling in identity theft protection and credit monitoring services; watch for suspicious communications claiming to be from healthcare providers, insurers, or financial institutions, and verify directly with organizations before providing information
Change passwords for any online healthcare portals and financial accounts, using strong, unique passwords; enable multi-factor authentication where available to add an additional security layer
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida
Technical Notes
University of Miami Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for University of Miami