CSIDB logo
Incident

Florida Healthy Kids Corporation

Incident posture

Attack window
Dec 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Florida Healthy Kids Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Florida Healthy Kids Corporation experienced a prolonged unauthorized access incident attributed to unpatched vulnerabilities in its web hosting vendor's systems, impacting applicants and enrollees. The breach exposed sensitive personal information including names, birthdates, Social Security numbers, financial records, family relationship details, and insurance information. An investigation determined the vendor failed to apply necessary security patches, allowing hackers to exploit the systems and alter some application addresses. The incident affected approximately 3.5 million individuals and was subsequently reported to federal authorities.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 9, 2020, Florida Healthy Kids Corporation (FHKC) disclosed a breach of its website affecting applicants and enrollees in the Florida KidCare program. The incident was attributed to Jelly Bean Communications Design, FHKC’s web hosting vendor for the prior seven years. Unpatched vulnerabilities in the vendor’s software allowed unauthorized access to personal information between November 2013 and the breach’s discovery date. Exposed data included full names, dates of birth, email and physical addresses, telephone numbers, Social Security Numbers, and detailed financial information such as wages, alimony, child support, royalties, other income sources, and tax deductions. Family relationships listed on applications and secondary insurance details were also compromised. FHKC confirmed the vendor identified the intrusion but did not specify the exact number of affected individuals at the initial disclosure.

An independent forensic investigation commissioned by FHKC determined that Jelly Bean Communications Design failed to apply necessary security patches, leaving the website susceptible to exploitation. Hackers manipulated data within the system, altering street addresses in some Florida KidCare applications. FHKC published an incident notice and FAQ on its website to inform the public, though it did not detail technical containment measures beyond terminating the vendor’s access. On February 12, 2021, the breach was reported to the U.S. Department of Health and Human Services as impacting 3.5 million individuals, reflecting the scale of exposure over the seven-year period. No additional attacker motives or methodologies were disclosed beyond the exploitation of unpatched software vulnerabilities.

Sources

Sources available to members: 1 source.

CSIDB