University of Mississippi Medical Center
ent_9670e515b879440402448509
Disclosures
2
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
7,492
as filed · HHS OCR MS
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Mississippi Medical Center
- Normalized
- university of mississippi medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- umc.edu
Disclosure history (2)newest first
- MSHHS OCRas victim2017-07-07
University of Mississippi Medical Center (MS) reported to HHS OCR on 2017-07-07 a Hacking/IT Incident affecting 7,492 individuals. On May 7, 2017, ransomware encrypted data on a segregated network server containing records from a legacy electronic medical record system last used ~May 2016. Affected data included demographic, clinical, and health insurance information. The CE was under an active OCR Corrective Action Plan at the time; it revised security policies, conducted an enterprise-wide risk analysis, and fulfilled all notification obligations. Breached info located on Electronic Medical Record and Network Server.
- MSHHS OCRas victim2013-03-21
University of Mississippi Medical Center (UMMC) reported to HHS OCR on 2013-03-21 a loss/theft incident affecting 500 individuals per the HHS portal (investigation revealed ~10,000 patients impacted). A password-protected laptop went missing from the MICU, likely stolen by a visitor. OCR also found a UMMC network drive broadly accessible via generic credentials over wireless, exposing ePHI of ~10,000 patients since 2008. UMMC paid a $2,750,000 settlement and adopted a corrective action plan. Breached information located on a Laptop.