The University of Texas MD Anderson Cancer Center
ent_4f7f33306b8f867965ca1f2c
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
29,021
as filed · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The University of Texas MD Anderson Cancer Center
- Normalized
- the university of texas md anderson cancer center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mdanderson.org
Disclosure history (4)newest first
- 🦀Maryland State AGas victim2025-03-12
The Seltzer Firm notified the Maryland AG of a data event involving one Maryland resident affiliated with The University of Texas MD Anderson Cancer Center. Unauthorized access occurred Dec 10-14, 2024. Impacted data included names, SSNs, driver's licenses, DOBs, and passport numbers. The firm engaged forensic specialists, notified law enforcement, and offered 12 months of credit monitoring.
- TEXASHHS OCRas victim2014-01-31
The University of Texas MD Anderson Cancer Center reported to HHS OCR on 2014-01-31 the loss of an unencrypted thumb drive (Other Portable Electronic Device) containing ePHI of 3,598 individuals. Exposed data included names, birthdates, diagnoses, lab results, medications, and treatment information. OCR pursued formal enforcement for failure to encrypt and impermissible ePHI disclosure. An ALJ and DAB upheld a civil money penalty, but the U.S. 5th Circuit vacated it; the DAB ultimately dismissed the case. No business associate was involved.
- TEXASHHS OCRas victim2013-01-24
The University of Texas MD Anderson Cancer Center reported to HHS OCR on 2013-01-24 a Theft affecting 29,021 individuals. Breached information was located on a Laptop. No business associate was involved. The incident involved theft of a laptop containing protected health information including patient health and identity data.
- TEXASHHS OCRas victim2012-08-17
The University of Texas MD Anderson Cancer Center reported to HHS on 2012-08-17 a Loss affecting 2264 individuals. Breached information located on Other Portable Electronic Device. An employee lost an unencrypted thumb drive containing names, dates of birth, lab results, and treatment information. OCR enforcement resulted in a vacated civil money penalty and case dismissal.