University of Rochester
ent_019ea8c734f6747165576230e0074f0b
Disclosures
7
State AG · Leak Site · HHS OCR · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
88,025
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- University of Rochester
- Normalized
- university of rochester— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300PEMUZY5D3ZXQ58
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rochester.edu
Disclosure history (7)newest first
- 🍁Vermont State AGas victim2023-07-28
University of Rochester notified Vermont AG of a data breach involving its MOVEit File Transfer vendor, Progress Software. An unauthorized third party exploited a vulnerability on May 27, 2023, to access personal information. Files containing personal info were potentially removed on July 19, 2023. The university engaged investigators and offered 24 months of credit monitoring.
- 🦞Maine State AGas victim2023-07-28
Maine AG notice for University of Rochester breach occurring 05/27/2023, discovered 07/19/2023. Third-party vendor unauthorized access exposed names and SSNs. 88,025 total individuals affected (91 Maine residents). Notification sent 07/28/2023 offering 2 years of Experian IdentityWorks.
- 🦬Montana State AGas victim2023-07-28
University of Rochester reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-28. The breach occurred from 5/29/2023 to 5/30/2023. 12 Montana residents were affected.
- 🐻California State AGas victim2023-07-28
University of Rochester notified individuals of a data breach involving its third-party vendor, Progress Software. An unauthorized party exploited a vulnerability in the MOVEit File Transfer solution between May 27 and May 31, 2023, to access and potentially exfiltrate personal information, including Social Security numbers. The University engaged outside professionals to investigate and is offering 24 months of complimentary identity protection services.
- GLOBALLeak Siteas victim2023-07-14
University of Rochester
- NEW YORKHHS OCRas victim2015-05-22
University of Rochester Medical Center and Affiliates reported to HHS OCR on 2015-05-22 an Unauthorized Access/Disclosure affecting 3,403 individuals via loss of an unencrypted flash drive (2013) and theft of an unencrypted laptop (2017). OCR found URMC failed to implement encryption and risk analysis. URMC agreed to pay $3 million and undertook a corrective action plan with two years of HIPAA compliance monitoring.
- NEW YORKHHS OCRas victim2010-05-20
University of Rochester Medical Center and Affiliates reported to HHS on 2010-05-20 an 'Other' breach (accidental misdelivery of paper records) affecting 2,628 individuals. On April 19, 2010, 2,628 patient billing statements for Strong Memorial Hospital were mailed to wrong patients. Statements contained names, addresses, SSNs, health insurance plan details, subscriber numbers, dollar amounts owed, and service descriptions. Breached information located on Paper/Films. Remediation included mechanical counters, per-run page reports, and manual QC envelope inspection.