DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

FL: Former Aventura Hospital employee charged criminally in ID theft scheme

Posted on April 9, 2015 by Dissent

Today, the U.S. Attorney’s Office for the Southern District of Florida revealed a prosecution stemming from an insider breach impacting Aventura Hospital patients, although I’m not confident I can figure out which Aventura Hospital breach this is related to (see PHIprivacy.net and this site for previous reports of Aventura Hospital insider breaches). Note that the employee reported that to avoid detection, he took screenshots of patient records and then printed out the screenshots. This is a method I’ve noted before on this site and on phiprivacy.net.

United States v. Jesney Eliassaint, Case No.15-2378-MJ-Simonton

On March 23, 2015, Jesney Eliassaint, 33, of Miami, was charged by criminal complaint for his involvement in an identity theft scheme.

According to the criminal complaint, in February 2014, officers with the Miami Gardens Police Department performed a traffic stop of a car for having an expired vehicle registration.  Inside the car were several iPads and sheets of paper containing (“PII”) – including names, dates of birth, and Social Security numbers – of various individuals.  A subsequent investigation by the USSS revealed that there were approximately 137 different names, with corresponding PII, printed on the sheets, some of which had the word “Patient” written across the top.  The USSS determined that the PII found in the vehicle originated from a data breach at Aventura Hospital.  The breach had been executed from Eliassaint’s computer in the hospital’s medical billing department.  According to Aventura Hospital, computer records revealed that Eliassaint had conducted approximately 4,000 inquiries for patients by their date of birth.

During the investigation, USSS agents interviewed Eliassaint, who admitted to conducting the searches and printing out patient records containing the PII while he was working as a contract employee for an outside company.  Eliassaint also told USSS agents that he would take screen shots of the patient records and then print them out to avoid detection.  Eliassaint stated that he sold the sheets of paper, containing PII, for approximately $100 per sheet, to several individuals.  Eliassaint estimated that he made a total of $2,000 for selling the patients’ information.

The defendant is charged with access device fraud and aggravated identity theft.


Related:

  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • NY: Gloversville hit by ransomware attack, paid ransom
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
Category: Health DataID TheftInsiderU.S.

Post navigation

← CareerSource South Florida employee stole and sold identity info on public benefits applicants
FL: Another prosecution of fraudsters using student information for tax refund fraud scheme →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • US, allies sanction Russian bulletproof hosting services for ransomware support
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • Large medical lab in South Africa suffers multiple data breaches
  • Report released on PowerSchool cyber attack
  • Sue The Hackers – Google Sues Over Phishing as a Service
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • Eurofiber admits crooks swiped data from French unit after cyberattack
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data
  • India’s Digital Personal Data Protection Act 2023 brought into force
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.