University of Wisconsin Hospitals and Clinics Authority
ent_019e10e1b3bd111f377687510c83cbe0
Disclosures
3
HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
85,902
nationwide · HHS OCR WI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Wisconsin Hospitals and Clinics Authority
- Normalized
- university of wisconsin hospitals and clinics authority— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300O76DW14JGO7224
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- WISCONSINHHS OCRas victim2024-03-05
University of Wisconsin Hospitals and Clinics Authority reported to HHS on 2024-03-05 a Hacking/IT Incident affecting 85,902 individuals. Breached information located on Email. An employee was targeted by a phishing scheme exposing PHI including names, DOBs, addresses, and diagnoses.
- WISCONSINHHS OCRas victim2021-06-18
University of Wisconsin Hospitals and Clinics Authority reported to HHS on 2021-06-18 a Hacking/IT Incident affecting 4563 individuals. Breached information located on Electronic Medical Record, Other. The cyber-attack affected PHI including names, dates of birth, addresses, claims, diagnoses, lab results, and medications. The entity notified HHS, individuals, and media, and implemented new policies, security awareness training, and additional safeguards.
- FEDERALHHS OCRas victim2016-09-30
The covered entity (CE), University of Wisconsin and Clinics Authority, reported that a survey was erroneously mailed to family members of 6,923 patients rather than to the patients directly. The breach occurred because of formatting problems sent in a data file to the CE’s business associate (BA). The PHI included patients’ names and the names of patients’ healthcare providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE initiated an internal investigation and developed an action plan to prevent similar disclosures, revised and redesigned processes for providing patient survey information, and trained pertinent staff on the new processes.