Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “florida” · 9 entries

Saint Pete MRI reports hacking incident affecting 138,209 patients

A Florida-based healthcare provider, MRI Associates of St. Pete, Inc. d/b/a Saint Pete MRI, filed a breach report with HHS OCR on August 19, 2025. The filing describes a hacking/IT incident involving a network server. The breach potentially affected 138,209 individuals. As a covered entity, the provider is required to notify affected patients and report the incident to the government. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

Wound Technology Network reports hacking incident affecting 139,830 patients

A Florida healthcare provider, Wound Technology Network, Inc., filed a breach report with HHS OCR on January 28, 2026. The filing details a hacking/IT incident that compromised the protected health information of 139,830 individuals. The unauthorized access occurred on a network server. As a covered entity, the provider is required to report breaches affecting 500 or more individuals within 60 days of discovery. This submission date reflects when the report was filed with the government, not necessarily when the breach occurred. Healthcare administrators should monitor such filings to understand the evolving threat landscape, particularly for providers managing sensitive wound care data. No further details on the specific nature of the data accessed or the timeline of the incident are provided in this summary.

Florida medical group reports hacking incident affecting 246,711 patients

A Florida healthcare provider, Medical Associates of Brevard, LLC, has filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on September 5, 2025, indicates that the personal information of 246,711 individuals was compromised. The breach occurred on a network server. As a covered entity, this provider is required to notify affected individuals and the Department of Health and Human Services. Healthcare administrators should monitor for similar threats to their own network infrastructure and ensure their incident response plans are current.

VITAS Hospice reports massive data breach affecting 319,177 individuals

A major hacking/IT incident at VITAS Hospice Services, LLC, a healthcare provider in Florida, has been reported to HHS OCR. The filing, submitted on November 24, 2025, indicates that the personal information of 319,177 individuals was compromised. The breach originated from a network server. As a covered entity, VITAS is required to notify affected individuals and report the incident to the government. Healthcare administrators should monitor for further details regarding the specific data types exposed, as this large-scale incident highlights the ongoing risks to provider networks.

Florida business associate reports massive hacking breach affecting 279,275 individuals

A Florida-based business associate, Zumpano Patricios, P.A., filed a report with HHS OCR regarding a hacking/IT incident. The breach affected 279,275 individuals, with unauthorized access occurring on a network server. The filing was submitted on July 3, 2025. As a business associate, this entity is bound by HIPAA obligations through its contracts with covered entities. Healthcare administrators should review their vendor contracts to ensure business associates have adequate security measures and breach notification protocols in place. This filing highlights the scale of potential exposure when network servers are compromised.

Retina Group of Florida reports hacking incident affecting 152,691 patients

A healthcare provider, Retina Group of Florida, filed a breach report with HHS OCR on September 3, 2025. The filing describes a hacking/IT incident that compromised data stored on a network server. The breach affected 152,691 individuals. This submission date is when the report was filed with the regulator, not necessarily when the incident occurred or was discovered. As a healthcare provider, this entity is a Covered Entity under HIPAA. Administrators at other organizations should note the scale of this incident involving a specialist group. Review your own incident response plans to ensure they address server-level compromises. Monitor for further details from the provider regarding the specific types of data exposed.

Modernizing Medicine reports hacking incident affecting nearly 200,000 patients

Business Associate Modernizing Medicine, Inc. filed a breach report with HHS OCR on October 17, 2025, describing a hacking/IT incident involving data on a network server. The filing covers 198,795 individuals. As a Business Associate, Modernizing Medicine provides services to covered entities; if your organisation uses their software, you should verify whether your patient data was among those affected. The submission date is when the report was filed with HHS, not necessarily when the breach occurred or was discovered. This is a reportable event under HIPAA breach notification rules.

Florida business associate reports hacking incident affecting 145,714 individuals

A Florida-based business associate, Operation PAR, Inc., filed a report with HHS OCR regarding a hacking/IT incident. The filing, submitted on June 25, 2026, indicates that 145,714 individuals were affected. The breach occurred on a network server. Because this entity is a business associate, its covered entities (such as health plans or providers) may need to verify their own notification obligations. Administrators should check if they contract with this vendor and review their business associate agreements for specific reporting requirements.

Escambia Community Clinics reports hacking incident affecting 143,969 patients

Escambia Community Clinics, Inc., operating as Community Health Northwest Florida, filed a breach report with HHS OCR on February 3, 2025. The healthcare provider disclosed that a hacking/IT incident compromised data stored on a network server. The filing indicates that 143,969 individuals were affected by this unauthorized access. As a covered entity, the clinic is required to report breaches of this scale. Administrators at similar community health centers and clinics should review their own server security protocols and incident response plans, noting that submission dates reflect when the report was filed, not necessarily when the breach occurred or was discovered.

← Back to AI Health Regulator News