University of Miami Health System Ensnared in Data Breach

An employee had gained unauthorized access to over 2,000 patient records.

By HFT Staff


The University of Miami has notified individuals whose personal health information was involved in an incident involving an employee. 

In June 2025, the University of Miami identified that an employee had viewed over 2,000 patient records between September 2022 and May 2025 without a legitimate business or clinical purpose. The University determined that the data viewed varied by patient but may have included elements such as first and last name, date of birth, medical record number, provider name, diagnosis/condition, insurance information and vaccination status. It’s important to note that no financial information, including Social Security numbers or credit data, was viewed during this incident. 

The employee was terminated, and the University is collaborating with law enforcement to pursue any necessary actions against the terminated employee. The University engaged Kroll, Inc. to send notifications by postal mail to all patients involved in this incident. 

Additionally, the University is continuing to work with cybersecurity experts to gather evidence, enhance their security measures and update their procedure practices to safeguard health information. 



August 26, 2025


Topic Area: Information Technology , Security


Recent Posts

Healthcare Security: To Arm Or Not To Arm?

Deciding whether or not to hire armed security personnel requires that managers understand a range of critical considerations.


False Alarm at Kansas Hospital Highlights Importance of Alarm System Reliability

After a two-hour search of the hospital and nearby medical facilities, no threat was found.


Integrated Oncology Network Caught Up in Data Breach

The network first learned of the incident on April 11, 2025.


ISSA Introduces Healthcare Platform to Advance Safer, Cleaner Patient Environments

This new resource integrates training, research and cross-sector collaboration to raise care standards and improve patient outcomes.


Third-Party Tracking Settlement is a Compliance Wake-Up Call for Healthcare Facilities Managers

Mount Sinai Health System agrees to a $5.3 million settlement to resolve claims it improperly shared patient data with Facebook through tracking tools.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.