University of Wisconsin Hospitals and Clinics Authority
bd_a2544acf933a4dcc · schema v1 · pii pii-v1
Full breach record for University of Wisconsin Hospitals and Clinics Authority →The covered entity (CE), University of Wisconsin and Clinics Authority, reported that a survey was erroneously mailed to family members of 6,923 patients rather than to the patients directly. The breach occurred because of formatting problems sent in a data file to the CE’s business associate (BA). The PHI included patients’ names and the names of patients’ healthcare providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE initiated an internal investigation and developed an action plan to prevent similar disclosures, revised and redesigned processes for providing patient survey information, and trained pertinent staff on the new processes.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 30, 2016
- Raw hash
- 01a1476e23a869adfc2b300f3e1e18680c8d6cec3238defe8a117507fb13e259
Source filing
Reporting entity
- Name
- University of Wisconsin Hospitals and Clinics Authoritynorm: university of wisconsin hospitals and clinics authority
- Industry
- Health Care Services
Victim entity
- Name
- University of Wisconsin Hospitals and Clinics Authoritynorm: university of wisconsin hospitals and clinics authority
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 6,923
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.