University of Oklahoma Department of Urology
bd_df843b03b71cc831 · schema v1 · pii pii-v1
Full breach record for University of Oklahoma Department of Urology →University of Oklahoma Department of Urology (operating as University of Oklahoma Health Sciences Center) reported to HHS OCR on 2015-10-10 a Theft breach affecting approximately 9,300 individuals. An unencrypted laptop used by a former physician in the Pediatric Urology program was stolen from his vehicle. PHI exposed included patients' names, medical record numbers, dates of birth, and in some cases age, physicians' names, and diagnosis/treatment/billing codes. The CE notified HHS, affected individuals, and media. OCR obtained assurances that corrective actions — including additional ePHI device safeguards, workforce retraining, and revised physician exit protocols — were implemented.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 10, 2015
- Raw hash
- 4aed58ea497d5105c59e806aff8e40bfe796a5936a8751976b41e963b72a847d
Source filing
Reporting entity
- Name
- University of Oklahoma Department of Urologynorm: university of oklahoma department of urology
- Industry
- Health Care Services
Victim entity
- Name
- University of Oklahoma Department of Urologynorm: university of oklahoma department of urology
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Oct 10, 2015
- Affected individuals
- 9,300
- Data types
- HEALTH_BASICIDENTITY_BASICMINOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR — corrective action assurances obtained
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Oct 10, 2015— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.