Circles of Care, Inc. Files Notice of Data Breach Affecting More Than 61k Patients

Console and Associates, P.C.
Contact

On January 3, 2023, Circles of Care, Inc. filed notice of a data breach with the U.S. Department of Health and Human Services Office for Civil Rights after confirming that an unauthorized party was able to access—and possibly steal—confidential patient information from the organization’s computer network. Based on the company’s official filing, the incident resulted in an unauthorized party gaining access to consumers’ first and last names, dates of birth, Social Security numbers, addresses, phone numbers, driver’s license numbers, bank routing and account numbers, medical account numbers, provider names, service dates, diagnosis, and medical procedure codes. After confirming that consumer data was leaked, Circles of Care began sending out data breach notification letters to all individuals who were impacted by the recent data security incident.

As a healthcare provider, Circles of Care has access to an incredible amount of personal and sensitive patient information. In the wrong hands, this information could be used to commit identity theft and other frauds against patients. For this reason, one would hope and expect that the organization would take the utmost care to keep intruders out of its computer system. However, as we’ve discussed in other posts, news of a data breach could be an indication that an organization failed to take its data security obligations seriously. If Circles of Care was negligent in how it stored patient data, victims of the breach may be able to pursue a data breach lawsuit against the company.

What We Know So Far About the Circles of Care Breach

The available information regarding the Circles of Care breach comes from the company’s filing with the U.S. Department of Health and Human Services Office for Civil Rights, as well as a notice posted on the company’s website. According to these sources, on September 21, 2022, Circles of Care detected suspicious activity within its computer network. In response, the organization secured its systems and then began working with outside data security specialists to investigate the incident and determine what, if any, patient data was exposed.

On November 29, 2022, Circles of Care confirmed through its investigation that an unauthorized actor was able to gain access to its computer network on September 6, 2022. It was also determined that the unauthorized actor may have removed certain files containing confidential patient information.

Upon discovering that sensitive patient data was available to an unauthorized party, Circles of Care began to review the affected files to determine what information was compromised and which consumers were impacted. While the breached information varies depending on the individual, it may include your first and last name, date of birth, Social Security number, address, phone number, driver’s license number, bank routing and account numbers, medical account number, provider names, service dates, diagnosis, and medical procedure codes.

On January 3, 2023, Circles of Care sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident. According to the U.S. Department of Health and Human Services Office for Civil Rights, the Circles of Care data breach affected 61,170 people.

More Information About Circles of Care, Inc.

Circles of Care, Inc. is a behavioral healthcare provider based in Valrico, Florida. The company provides mental health services, alcohol and drug abuse services and other related services to patients through a variety of hospital-based and state and county-contracted programs. Circles of Care operates multiple locations, including:

  • North Area Outpatient

  • Central Area Outpatient

  • South Area Outpatient

  • Sheridan Oaks

  • Twin Rivers

  • Children’s Crisis Stabilization Unit

  • Harbor Pines

  • Outreach

  • Cedar Village

  • Community Support Services

Circles of Care employs more than 435 people and generates approximately $40 million in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Console and Associates, P.C.

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide