Jackson Health System fires employee over five-year patient data snooping

Organization
Jackson Health System
Exploit
Malicious Insider
Industry
Healthcare

Jackson Health System, the public hospital network serving Miami-Dade County, said it had dismissed an employee who accessed patient records without a legitimate work reason over a period of almost five years. The unauthorized access ran from July 2020 until it was identified in May 2025.

The health system said the worker used the access to promote a personal healthcare business. The information involved included patient names, dates of birth, addresses, medical record numbers and clinical details. Jackson said Social Security numbers were not among the data viewed.

Accounts of the scale differed slightly. Jackson's statement and local coverage referred to more than 2,000 patients, while the HIPAA Journal reported a figure of 2,599. The employee was terminated once the conduct was confirmed, affected patients were notified, and the health system said it was working with law enforcement on possible criminal HIPAA violations and had tightened controls on access to patient records.

The disclosure followed an earlier insider case at the same organization. Jackson reported in 2016 that an employee had improperly accessed the records of 24,188 patients, also over roughly five years. The U.S. Department of Health and Human Services Office for Civil Rights imposed a $2.15 million penalty in 2019 after an investigation that found compliance failures including inadequate review of system activity logs.

Sources