University of Michigan/Michigan Medicine
ent_ce475fecd1491769c3f14180
Disclosures
8
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
56,953
nationwide · HHS OCR MI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Michigan/Michigan Medicine
- Normalized
- university of michigan michigan medicine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- med.umich.edu
Disclosure history (8)newest first
- MIHHS OCRas victim2026-05-01
University of Michigan/Michigan Medicine reported to HHS OCR on 2026-05-01 an Unauthorized Access/Disclosure breach affecting 551 individuals. Breached information was located in Electronic Medical Records. No business associate was identified as involved. The covered entity is a healthcare provider and academic medical center in Michigan.
- MIHHS OCRas victim2025-08-13
University of Michigan/Michigan Medicine reported to HHS on 2025-08-13 an Unauthorized Access/Disclosure affecting 1,015 individuals. An employee mailed a postcard that exposed PHI, including names, addresses, and diagnoses/conditions. Breached information was on paper/films. The CE notified HHS, affected individuals, and the media. Additional administrative and technical safeguards were implemented and staff were retrained.
- MIHHS OCRas victim2024-07-19
University of Michigan/Michigan Medicine reported to HHS on 2024-07-19 a Hacking/IT Incident affecting 56,953 individuals. Breached information located on Email. An employee was targeted by an email phishing scheme exposing PHI including names, addresses, DOB, SSNs, and diagnoses. Corrective actions included technical safeguards and HIPAA training.
- MIHHS OCRas victim2022-03-03
University of Michigan/Michigan Medicine reported to HHS on 2022-03-03 a Hacking/IT Incident affecting 2,921 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme. PHI involved included names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, and the media, and provided substitute notice. In its mitigation efforts, the CE strengthened its administrative and technical safeguards and retrained staff on email security precautions.
- MIHHS OCRas victim2020-10-16
University of Michigan/Michigan Medicine reported to HHS on 2020-10-16 a Unauthorized Access/Disclosure affecting 1062 individuals. Breached information located on Email. An employee inadvertently sent an email containing ePHI (names, email addresses, diagnoses) without using bind carbon copy. The CE sanctioned the employee and retrained the workforce.
- MIHHS OCRas victim2019-08-16
University of Michigan/Michigan Medicine reported to HHS on 2019-08-16 a Hacking/IT Incident affecting 5466 individuals. Breached information located on Email. An employee was victim of an email phishing scheme exposing PHI including names, DOB, SSN, diagnoses, and lab results. The entity implemented safeguards and retrained employees.
- MIHHS OCRas victim2018-09-28
University of Michigan/Michigan Medicine reported to HHS on 2018-09-28 a Unauthorized Access/Disclosure affecting 3624 individuals. Breached information located on Paper/Films. Business associate University Lithoprinters, Inc. inadvertently mailed PHI (names, addresses, phone, email) to wrong recipients.
- MIHHS OCRas victim2018-06-25
University of Michigan/Michigan Medicine reported to HHS on 2018-06-25 a Theft affecting 871 individuals. Breached information located on Laptop. PHI involved names, dates of birth, diagnoses, lab results, medications, and treatment information. The entity notified HHS, individuals, and media, and implemented additional safeguards and staff retraining.