DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

FL: Three Sentenced in Orange County Health Department Identity Theft Scheme (update 1)

Posted on March 4, 2014 by Dissent

There’s a follow-up to a breach noted previously on this blog:

U.S. District Judge Roy B. Dalton, Jr. sentenced Delray Duncan, Gerald Williams, and Shanterica Smith to federal prison yesterday for identity theft. Specifically, the court sentenced Duncan to 42 months in federal prison, Williams to 54 months in federal prison, and Smith to 60 months in federal prison. All three were also ordered to pay restitution in the amount of $1 million. Each previously pleaded guilty for their roles in this case.

According to court documents, the Internal Revenue Service, the Federal Bureau of Investigation, and the United States Postal Inspection Service initiated an investigation after the Orange County Sheriff’s Office executed an unrelated search warrant and discovered a list of names, dates of birth, and Social Security numbers. Further investigation revealed that Williams and Smith worked at the Orange County Health Department (OCHD). Williams and Smith accessed personal identifying information (PII) of OCHD patients and provided that information to a third party who filed fraudulent tax returns in the names of those patients. Williams and Smith did not know each other while working at OCHD but ultimately provided the information to the same person. Williams provided the PII to Duncan who, in turn, provided the PII to others in order to file the fraudulent tax returns. Smith provided the PII directly to those responsible for filing fraudulent tax returns.

In total, Williams and Smith stole the identities of approximately 2,200 patients. Fraudulent tax returns totaling approximately $3.9 million were filed using the stolen PII. The investigation into those responsible for filing the fraudulent tax returns and those who obtained the proceeds from the fraudulently filed returns is ongoing.

This case was investigated by the Internal Revenue Service-Criminal Investigation, the Federal Bureau of Investigation, and the United States Postal Inspection Service. It was prosecuted by Assistant United States Attorney Shawn P. Napier.

SOURCE: U.S. Attorney’s Office, Middle District of Florida

Come to think of it, why haven’t we ever seen this on HHS’s public breach tool?  Time to email HHS again, I guess…

Updated March 26: I received a response to my inquiry to HHS, who confirmed that this breach was reported to them in December 2013, and they were working to correct the public breach tool. The Florida Dept. of Health had announced the breach publicly on October 30, right after being informed by law enforcement.

No related posts.

Category: Health Data

Post navigation

← Faxes containing patient data breached from Roper Hospital (Updated)
Ca: Privacy breach at London Shoppers Drug Mart stuns customer →

1 thought on “FL: Three Sentenced in Orange County Health Department Identity Theft Scheme (update 1)”

  1. Anonymous says:
    March 5, 2014 at 7:13 pm

    Thank you for sharing.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Integrated Oncology Network victim of phishing attack; multiple locations affected (2)
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
  • Five youths arrested on suspicion of phishing
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
  • Kentfield Hospital victim of cyberattack by World Leaks, patient data involved
  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.