UNIVERSITY OF KENTUCKY
ent_019e21801e53863f5a1b4d85c635b9da
Disclosures
2
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
2,027
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UNIVERSITY OF KENTUCKY
- Normalized
- university of kentucky— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300V5YG1VXZAU5G02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 🐻California State AGas victim2021-08-05
University of Kentucky disclosed a data breach involving its OTIS Digital Driver’s License database. An unknown party exploited a website vulnerability between January 8 and February 6, 2021, acquiring a copy of the database containing usernames, passwords, and government-issued driver's license data. The breach was discovered during a penetration test in June 2021. The university fixed the vulnerability, disabled compromised passwords, and engaged forensic investigators.
- FEDERALHHS OCRas victim2010-06-18
A laptop computer containing the protected health information (PHI) of approximately 2,027 individuals was stolen from the University of Kentucky's Department of Pediatrics. The breach, reported to HHS on June 18, 2010, involved a laptop from the New Born Screening Program. The compromised data included names, addresses, dates of birth, social security numbers, and clinical information. In response to an OCR investigation, the university enhanced its encryption, conducted staff training on security and facility procedures, improved physical safeguards, and updated its policies on disclosure accounting.