University of Florida Notifies More Than 5K Patients of Data Breach | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

University of Florida Notifies More Than 5K Patients of Data Breach

May 30, 2013
by Rajiv Leventhal
| Reprints

An employee working at a University of Florida (UF) medical practice who had ties to an identity theft ring may have compromised patient personal and health information, according to UF officials.

UF is notifying 5,682 patients and parents of patients at the UF Pediatric Primary Care Clinic at Tower Square that they should take appropriate measures to protect themselves from identity theft. UF is offering fraud resolution services for those who suspect or confirm identity theft associated with this incident; the fraud service offer is good for one year.

“We deeply regret what happened and share the frustration associated with this situation,” Susan Blair, chief privacy officer for the University of Florida, said in a statement. “Protecting patient information is a top priority for us, and we are committed to finding new ways to identify and help prevent employee misconduct.”

The Office of the State Attorney, the Internal Revenue Service and the U.S. Secret Service are continuing to investigate a statewide identity theft ring. The university learned of the alleged incident from state and federal law enforcement officials on April 11. The employee may have used pediatric patient records to steal personal information including names, addresses, dates of birth and Social Security numbers. The employee was terminated, and law enforcement is taking action against the individual.

After notification from the Secret Service, UF cooperated with law enforcement and conducted a separate investigation about the use of patient records. This review determined that some patient records were accessed inappropriately. But because the employee also was assigned to access records as part of their job responsibilities, it was not possible to determine whether the information was misused.

The letters sent to parents and patients include information about the incident, steps they can take to protect themselves, information about identity monitoring services and steps recommended by the U.S. Federal Trade Commission about checking credit reports.

Topics

News

HealthlinkNY’s Galanis to Step Down as CEO

Christina Galanis, who has served as president and CEO of HealthlinkNY for the past 13 years, will leave her position at the end of the year.

Email-Related Cyber Attacks a Top Concern for Providers

U.S. healthcare providers overwhelmingly rank email as the top source of a potential data breach, according to new research from email and data security company Mimecast and conducted by HIMSS Analytics.

Former Health IT Head in San Diego County Charged with Defrauding Provider out of $800K

The ex-health IT director at North County Health Services, a San Diego County-based healthcare service provider, has been charged with spearheading fraudulent operations that cost the organization $800,000.

Allscripts Touts 1 Billion API Shares in 2017

Officials from Chicago-based health IT vendor Allscripts have attested that the company has reached a new milestone— one billion application programming interface (API) data exchange transactions in 2017.

Dignity Health, CHI Merging to Form New Catholic Health System

Catholic Health Initiatives (CHI), based in Englewood, Colorado, and San Francisco-based Dignity Health officially announced they are merging and have signed a definitive agreement to combine ministries and create a new, nonprofit Catholic health system.

HHS Announces Winning Solutions in Opioid Code-a-Thon

The U.S. Department of Health and Human Services (HHS) hosted this week a first-of-its-kind two-day Code-a-Thon to use data and technology to develop new solutions to address the opioid epidemic.