University of North Carolina at Chapel Hill School of Medicine
ent_5cdb492ff6fa88c57e38ceeb
Disclosures
3
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
3,716
as filed · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of North Carolina at Chapel Hill School of Medicine
- Normalized
- university of north carolina at chapel hill school of medicine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- med.unc.edu
Disclosure history (3)newest first
- NCHHS OCRas victim2025-09-19
The University of North Carolina at Chapel Hill - School of Medicine reported to HHS on 2025-09-19 a Hacking/IT Incident affecting 799 individuals. Breached information located on Email. An employee was targeted by an email phishing scheme exposing demographic, financial, and clinical PHI. The entity implemented additional administrative, technical, and security safeguards.
- NCHHS OCRas victim2021-07-19
The University of North Carolina at Chapel Hill School of Medicine reported to HHS on 2021-07-19 a Hacking/IT Incident (email phishing attack) affecting 2,718 individuals. An employee was the victim of a phishing attack via Email. PHI exposed included names, addresses, dates of birth, diagnoses, health insurance information, driver's license and Social Security numbers, and other treatment information. The CE notified HHS, affected individuals, and the media, offered credit monitoring, and implemented additional technical safeguards.
- NCHHS OCRas victim2019-11-12
University of North Carolina at Chapel Hill School of Medicine reported to HHS on 2019-11-12 a Hacking/IT Incident (email phishing scheme) affecting 3,716 individuals. Several employees were victims of a phishing attack that compromised PHI including Social Security numbers, financial information, diagnoses, treatment, and clinical information. Breached information was located in Email. The CE provided credit monitoring and retrained staff on email security.