UMASSAmherst
ent_a4a2de815afa3b222c9de60e
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,670
as filed · HHS OCR MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UMASSAmherst
- Normalized
- umassamherst— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- umass.edu
Disclosure history (2)newest first
- 🏛️Massachusetts State AGas victim2026-07-01
University of Massachusetts Amherst notified individuals on July 20, 2026, regarding a data security event involving names, addresses, Social Security numbers, and bank account/routing numbers. The university offered two years of Experian IdentityWorks. The incident status is contained, with no specific discovery or occurrence dates provided in the notice.
- MASSACHUSETTSHHS OCRas victim2013-06-05
University of Massachusetts Amherst (UMass) reported to HHS OCR on 2013-06-05 a Hacking/IT Incident affecting 1,670 individuals. A workstation at UMass's Center for Language, Speech, and Hearing was infected with a generic remote access Trojan (RAT), exposing ePHI including names, addresses, SSNs, dates of birth, health insurance information, diagnoses, and procedure codes. UMass lacked a firewall. HHS OCR settled for $650,000 with a corrective action plan. Breached information located on a Desktop Computer.