University of Washington
ent_019e58eb246e0dd311622fb818e362b4
Disclosures
12
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
974,351
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Washington
- Normalized
- university of washington— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- T8YS5W0N70BYCTHPA429
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- uwmedicine.org
Disclosure history (12)newest first
- Washington State AGas victim2023-02-17
University of Washington inadvertently uploaded a research data file containing personal and health information of 534 individuals to a public website on Feb 4, 2022. The file was removed within minutes. Notifications were sent to affected individuals in 2023. Data included names, DOB, addresses, phone numbers, and COVID-19 test results.
- Washington State AGas victim2022-09-22
Kaye-Smith, a mailing service provider for UW Medicine, disclosed a ransomware attack affecting patient billing data. The incident involved the compromise of files containing patient names, medical record numbers, and billing details. The attack was detected in late May 2022, and 3,707 Washington residents were notified in August 2022.
- WASHINGTONHHS OCRas reporting2022-09-21
UW Medicine (WA), a healthcare provider, reported to HHS on 2022-09-21 a Hacking/IT Incident affecting 3,804 individuals. A cyber-attack on UW Medicine's business associate compromised PHI including names, addresses, claims and financial information, medical record numbers, and treatment information stored on a Network Server. The covered entity and BA notified HHS, affected individuals, and the media. Mitigation included complimentary credit monitoring and additional administrative and technical safeguards. OCR provided technical assistance regarding the HIPAA Rules.
- WASHINGTONHHS OCRas reporting2022-06-15
UW Medicine (WA) reported to HHS on 2022-06-15 a Theft affecting 763 individuals. The covered entity's office was burglarized and a laptop containing PHI was stolen. PHI involved included names, dates of birth, diagnoses, and other treatment information. Breached information located on Laptop. The CE notified HHS, affected individuals, the media, and provided substitute notice. Additional safeguards were implemented and staff were retrained.
- WASHINGTONHHS OCRas reporting2021-06-04
UW Medicine (WA) reported to HHS on 2021-06-04 a Hacking/IT Incident affecting 18,389 individuals. A business associate experienced a ransomware attack impacting ePHI stored on a Network Server. Exposed data included names, dates of birth, and medications prescribed. UW Medicine notified HHS, affected individuals, the media, and provided substitute notice. In response, the CE implemented additional technical safeguards and retrained staff.
- Oregon State AGas victim2019-02-25
University of Washington Medicine reported a data breach to the Oregon Attorney General. The breach was reported on 2019-02-25. The breach occurred during 12/4/2018 - 1/10/2019. The breach was discovered on 12/26/2018. 974,351 individuals were affected. Notice was sent on 2/19/2019.
- Montana State AGas reporting2019-02-20
UW Medicine disclosed a data breach in Montana where a database misconfiguration exposed protected health information (PHI) including names and medical record numbers. The incident was discovered on December 26, 2018, and notification letters were sent in February 2019. No SSNs or financial data were involved.
- Washington State AGas victim2019-02-20
University of Washington Medical Center disclosed a security incident where a database configuration error exposed internal files containing PHI (names, medical record numbers, treatment descriptions) to the internet. The breach affected approximately 974,351 individuals, with 894,272 in Washington. Discovery occurred on Dec 26, 2018, after the exposure began on Dec 4, 2018. No SSNs or financial data were involved. Remediation included suspending server changes, engaging consultants, and disabling directory browsing.
- WASHINGTONHHS OCRas reporting2019-02-20
UW Medicine reported to HHS on 2019-02-20 a Hacking/IT Incident affecting 973024 individuals. Breached information located on Network Server. A configuration error resulted in PHI (names and medical record numbers) becoming accessible on the internet.
- California State AGas victim2019-02-20
UW Medicine disclosed a data breach involving protected health information (PHI) due to a database configuration error. The error made internal reporting files containing names, medical record numbers, and descriptions of reported health information available on the internet between December 4, 2018, and January 10, 2019. UW Medicine became aware of the issue on December 26, 2018, and immediately removed the files. No medical records, financial information, or Social Security numbers were exposed. The incident was reported to the Office for Civil Rights.
- WASHINGTONHHS OCRas victim2013-11-27
University of Washington Medicine reported to HHS on 2013-11-27 a Hacking/IT Incident affecting 90,000 individuals. Malicious malware was introduced via an email attachment, compromising e-PHI including names, MRNs, SSNs, and financial data. The organization settled with OCR for $750,000 and entered a corrective action plan.
- Massachusetts State AGas victim2013-10-15
Washington University reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-10-15. 17 Massachusetts residents were affected. The report records the breach type as undefined.