Upmc
ent_019e07c59f5baee9301c74da217dfc3d
Disclosures
3
HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
2,259
as filed · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Upmc
- Normalized
- upmc— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001YCBUGKVU74S74
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- upmc.com
Disclosure history (3)newest first
- PAHHS OCRas victim2026-03-14
UPMC (Pennsylvania) reported to HHS OCR on 2026-03-14 an Unauthorized Access/Disclosure breach affecting 687 individuals. Breached information was located in an 'Other' location type. No business associate was involved. No further detail is available from the HHS web description.
- PAHHS OCRas victim2015-05-15
UPMC (PA) reported to HHS OCR on 2015-05-15 a Theft/insider-disclosure breach affecting 2,259 individuals. A business associate employee disclosed patients' PHI — including names, dates of birth, and Social Security numbers — to outside parties. The covered entity terminated its relationship with the business associate following the incident. OCR reviewed UPMC's risk analysis for Security Rule compliance. Breached information location: Other.
- PAHHS OCRas victim2013-11-27
UPMC (PA) reported to HHS on 2013-11-27 an Unauthorized Access/Disclosure breach affecting 1,279 individuals. An employee impermissibly accessed PHI stored in Electronic Medical Records, including names, dates of birth, Social Security numbers, addresses, and clinical information. UPMC notified HHS, affected individuals, and the media. The employee was sanctioned and law enforcement was notified. OCR reviewed UPMC's risk analysis for Security Rule compliance.