Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireCybersecurity NewsHospitals & Medical Centers

Broward Health data breach affected 1.3m patients, staff

By Maria Henriquez
healthcare-cybersecurity-freepik1170x658.jpg

Image by Freepik

January 5, 2022

Broward Health, a healthcare system in South Florida, suffered a data breach in October 2021 that impacted patient and employee personal information. 


The personal medical information accessed included name, date of birth, address, phone number, financial or bank account information, Social Security number, insurance information and account number, medical information including history, condition, treatment and diagnosis, medical record number, driver’s license number and email address. This personal information was exfiltrated (removed from Broward Health’s systems); however, there is no evidence that the information was actually misused. 


In a data breach notification to the Office of the Maine Attorney General, Broward Health said 1,357,879 were affected by the breach.


On October 15, 2021, attackers accessed the healthcare system’s network through a third-party medical provider. Broward Health discovered the intrusion on October 19, 2021, and quickly contained the incident, notified the Federal Bureau of Investigation (FBI) and the Department of Justice (DOJ), reset all employee passwords and engaged an independent cybersecurity firm to conduct the investigation. The DOJ requested that Broward Health delay the notification to ensure that it does not compromise the ongoing law enforcement investigation. 


A data review specialist conducted an extensive analysis of the data to determine what was impacted, which determined that some patient and employee personal information may have been impacted. 


While Broward Health has no evidence that employee or patient information has been used to commit fraud, patients and staff should take steps to protect against medical identity theft. This type of theft occurs when someone uses an individual’s name and sometimes other identifying information without the individual’s knowledge to obtain medical services or products or to fraudulently bill for medical services that have not been provided, Broward Health says. 


According to Broward Health, they have taken several steps to enhance security measures across the enterprise, including implementing multi-factor authentication for all users of its systems. Additional minimum-security requirements for devices not managed by Broward Health Information Technology (IT) with access to its network have also been implemented.


Adir Gruss, vice president of technical solutions at Laminar, says, “Organizations must take a data-centric approach to security in order to uplevel overall risk posture. The biggest challenge impeding data security teams today is that as more and more organizations move toward the cloud, they have lost track of where sensitive data resides. You simply cannot protect what you don’t know about. In order to protect against a majority of today’s cyberattacks, IT teams must prioritize visibility into cloud data, including supply chain access. With that knowledge, data protection teams can move from gatekeepers to enablers.”


Steve Moore, chief security strategist at Exabeam, notes, “No matter how robust your security stack is, your organization can still be vulnerable to intrusions stemming from compromised credentials — especially those that belong to third-party vendors and partners. According to the Verizon 2021 Data Breach Investigations Report, over 80% of breaches involve brute force attacks or the use of lost or stolen credentials. Giving network access to third parties only increases risk. As a result, even the best organizations must manage this problem perfectly to avoid adverse outcomes as well as ensure that partners are up to the same security standards, and perfect is difficult. Proper training, feedback loops, visibility, and effective technical capabilities are the keys to managing the risk of compromised insiders and external adversaries to protect important health information.


Moore adds, “A helpful defender capability is the development of a baseline for normal employee and third-party vendor behavior that can assist organizations with identifying compromised credentials and related intrusions. If you can establish normal behavior first, only then can abnormal be known — a great asset in uncovering unknowingly compromised credentials.”

KEYWORDS: cyber security data breach healthcare patient privacy

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Maria Henriquez is a former Associate Editor of Security. She covered topics including cybersecurity and physical security, risk management and more.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Figure 3- boonedam

    GoDaddy Confirms Data Breach - 28,000 Customers Affected

    See More
  • EasyLobby Visitor Management Protects Patients, Staff and Visitors at Hospitals and Healthcare Facilities

    See More
  • data-breach-freepik1170x658x4.jpg

    SuperCare Health discloses data breach affecting 300k individuals

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing