25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Florida Medical Clinic Notifies 1,000 Patients of Privacy Breach

Florida Medical Clinic, PA., has notified 1,000 patients that their due balance statements were exposed online as a result of a misconfiguration of its Patient Portal.

Between November 18, and January 6, 2016., due balance statements of some patients were viewed by industrial account patients when they logged onto the Patient Portal. Only a limited amount of patient data was viewable so there is not believed to be a high risk of patients coming to harm or suffering losses as a result of the breach.

Patients’ names, mailing address, provider names, dates of service, descriptions of procedures, and charges due were viewable by individuals unauthorized to view the information. At no point were Social Security numbers, dates of birth, credit card numbers, financial information, or other highly sensitive data accessed.

Upon discovery of the HIPAA Privacy Rule violation, Florida Medical Clinic launched an investigation which revealed that the vendor of its Patient Portal – Greenway Health – had turned on a setting on the Portal by accident which resulted in due balance statements being viewable by other individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The patients affected by the breach were those that used a guarantor to pay for medical services received from Florida Medial Clinic. Guarantors include organizations that conduct pre-employment screenings and supply them to potential employees. Affected individuals had their statements viewed by another member who was also on the victim’s industrial account.

Upon discovery of the misconfiguration, access to accounts was shut down to prevent any further privacy breaches until the problem was resolved. Florida Medical Clinic has also worked with its vendor to develop new protocols to prevent similar breaches from occurring in future.

Florida Medical Clinic has not received any reports to suggest the privacy breach has resulted in patients coming to harm, or that patient data have been used inappropriately. Patients concerned about the exposure of the above information can obtain a copy of their credit report from any of the three credit reference agencies without charge.

Florida Medical Clinic has advised patients that since they are entitled to one free report from Equifax, Experian, and TransUnion once every twelve months, they should obtain the reports one at a time and should spread them out to get the maximum benefit.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist