UT Southwestern Medical Center
ent_4bbc444941423594c7eb45fe
Disclosures
7
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
98,437
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UT Southwestern Medical Center
- Normalized
- ut southwestern medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- utsouthwestern.edu
Disclosure history (7)newest first
- ⭐Texas State AGas victim2026-02-13
UT Southwestern Medical Center based in Dallas, Texas, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-01-14 and reported on 2026-02-13. 424 Texas residents were affected. 433 individuals affected in total. Types of information involved: Name of individual;Medical Information;Other;Date of Birth. Consumers were notified via U.S. Mail.
- TEXASHHS OCRas victim2024-12-09
UT Southwestern Medical Center reported to HHS on 2024-12-09 a Unauthorized Access/Disclosure affecting 43,048 individuals. Breached information located on Email. Multiple employees impermissibly disclosed PHI using a calendar app.
- TEXASHHS OCRas victim2024-09-24
UT Southwestern Medical Center reported to HHS on 2024-09-24 a Unauthorized Access/Disclosure affecting 778 individuals. Breached information located on Electronic Medical Record. An unauthorized workforce member impersonated another employee to access PHI including names, addresses, SSNs, and treatment data. The entity sanctioned the employee and revised hiring processes.
- TEXASHHS OCRas victim2024-03-27
UT Southwestern Medical Center (TX) reported to HHS on 2024-03-27 an Unauthorized Access/Disclosure affecting 2,045 individuals. Breached information was located on a Network Server. Workforce members impermissibly disclosed PHI — including names, addresses, dates of birth, financial information, diagnoses, conditions, and other treatment information — without appropriate contractual agreements in place. The CE sanctioned the involved workforce members, implemented additional technical safeguards, and provided additional HIPAA training.
- FEDERALHHS OCRas victim2023-07-24
UT Southwestern Medical Center reported to HHS on 2023-07-24 a Hacking/IT Incident affecting 98,437 individuals. The breach involved a software application exposing protected health information (PHI) located on a network server. The PHI included names, dates of birth, addresses, Social Security numbers, diagnoses, claims, health insurance information, and other treatment information. In response, the entity offered complimentary credit monitoring and implemented additional security safeguards.
- TEXASHHS OCRas victim2021-02-05
UT Southwestern Medical Center reported to HHS on 2021-02-05 a Unauthorized Access/Disclosure affecting 3640 individuals. Breached information located on Other. An employee sent an email to a business associate without a BAA in place, exposing names and email addresses.
- TEXASHHS OCRas victim2020-08-13
UT Southwestern Medical Center reported to HHS on 2020-08-13 a Unauthorized Access/Disclosure affecting 15,535 individuals. Breached information located on Other. A workforce member sent electronic protected health information (ePHI) to an unauthorized entity. The entity retrained staff on safeguarding ePHI.