THE UNIVERSITY OF CHICAGO MEDICAL CENTER
bd_579dc4b435838e45 · schema v1 · pii pii-v1
Full breach record for THE UNIVERSITY OF CHICAGO MEDICAL CENTER →University of Chicago Medical Center (IL) reported to HHS on 2024-05-24 a Hacking/IT Incident (email phishing attack) affecting 10,332 individuals. Multiple employees were targeted in the phishing campaign. PHI exposed included names, dates of birth, Social Security numbers, passport numbers, driver's license/state ID numbers, financial information, diagnoses, medications, and health insurance/treatment information. Breached information located in Email. No business associate was involved. The CE offered credit monitoring and enhanced security safeguards; staff were retrained on email security.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6f1b677e1645896eMaine State AGfiled 2024-05-24Verified
- bd_95695ad34ba421f9Indiana State AGfiled 2024-05-24Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 24, 2024
- Raw hash
- 96e418b460ae9e1b22a7aea9076241bdd30b0b0be0a783d102e7f624deed3565
Source filing
Reporting entity
- Name
- THE UNIVERSITY OF CHICAGO MEDICAL CENTERnorm: the university of chicago medical center
- Domain
- uchicagomedicine.org
- Industry
- Health Care Services
Victim entity
- Name
- THE UNIVERSITY OF CHICAGO MEDICAL CENTERnorm: the university of chicago medical center
- Domain
- uchicagomedicine.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 28, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 10,332
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- HHS OCR notified
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 28, 2024→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.