University of Michigan/Michigan Medicine
ent_ce475fecd1491769c3f14180
Disclosures
12
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
57,891
nationwide · HHS OCR MI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of Michigan/Michigan Medicine
- Normalized
- university of michigan michigan medicine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- med.umich.edu
Disclosure history (12)newest first
- MICHIGANHHS OCRas victim2026-05-01
University of Michigan/Michigan Medicine reported to HHS OCR on 2026-05-01 an Unauthorized Access/Disclosure breach affecting 551 individuals. Breached information was located in Electronic Medical Records. No business associate was identified as involved. The covered entity is a healthcare provider and academic medical center in Michigan.
- MICHIGANHHS OCRas victim2025-08-13
University of Michigan/Michigan Medicine reported to HHS on 2025-08-13 an Unauthorized Access/Disclosure affecting 1,015 individuals. An employee mailed a postcard that exposed PHI, including names, addresses, and diagnoses/conditions. Breached information was on paper/films. The CE notified HHS, affected individuals, and the media. Additional administrative and technical safeguards were implemented and staff were retrained.
- MICHIGANHHS OCRas victim2024-09-26
University of Michigan/Michigan Medicine reported to HHS on 2024-09-26 a Hacking/IT Incident affecting 57,891 individuals. Breached information located on Email. PHI involved names and diagnoses/conditions. The entity changed passwords, strengthened requirements, implemented technical safeguards, revised policies, sanctioned staff, and provided training.
- Montana State AGas victim2024-07-31
Michigan Medicine reported a cyberattack between May 23-29, 2024, where attackers used pretexting to compromise three employee email accounts. Compromised emails contained patient PHI including names, medical record numbers, DOBs, and treatment info. No SSNs or financial data were involved. The incident was contained, reported to law enforcement and HHS OCR.
- MICHIGANHHS OCRas victim2024-07-19
University of Michigan/Michigan Medicine reported to HHS on 2024-07-19 a Hacking/IT Incident affecting 56,953 individuals. Breached information located on Email. An employee was targeted by an email phishing scheme exposing PHI including names, addresses, DOB, SSNs, and diagnoses. Corrective actions included technical safeguards and HIPAA training.
- Montana State AGas victim2022-11-10
Michigan Medicine notified Montana residents of a phishing incident (Aug 15-23, 2022) where employee credentials were compromised. Compromised email accounts contained patient PHI including names, DOBs, and medical records. No SSNs or financial data were involved. Accounts were disabled on Aug 23, 2022. Notices sent Oct 26, 2022.
- MICHIGANHHS OCRas victim2022-10-25
University of Michigan/Michigan Medicine reported to HHS on 2022-10-25 a Hacking/IT Incident affecting 33,857 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme affecting PHI including names, addresses, DOB, SSNs, and health data.
- MICHIGANHHS OCRas victim2022-03-03
University of Michigan/Michigan Medicine reported to HHS on 2022-03-03 a Hacking/IT Incident affecting 2,921 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme. PHI involved included names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, and the media, and provided substitute notice. In its mitigation efforts, the CE strengthened its administrative and technical safeguards and retrained staff on email security precautions.
- MICHIGANHHS OCRas victim2020-10-16
University of Michigan/Michigan Medicine reported to HHS on 2020-10-16 a Unauthorized Access/Disclosure affecting 1062 individuals. Breached information located on Email. An employee inadvertently sent an email containing ePHI (names, email addresses, diagnoses) without using bind carbon copy. The CE sanctioned the employee and retrained the workforce.
- MICHIGANHHS OCRas victim2019-08-16
University of Michigan/Michigan Medicine reported to HHS on 2019-08-16 a Hacking/IT Incident affecting 5466 individuals. Breached information located on Email. An employee was victim of an email phishing scheme exposing PHI including names, DOB, SSN, diagnoses, and lab results. The entity implemented safeguards and retrained employees.
- MICHIGANHHS OCRas victim2018-09-28
University of Michigan/Michigan Medicine reported to HHS on 2018-09-28 a Unauthorized Access/Disclosure affecting 3624 individuals. Breached information located on Paper/Films. Business associate University Lithoprinters, Inc. inadvertently mailed PHI (names, addresses, phone, email) to wrong recipients.
- MICHIGANHHS OCRas victim2018-06-25
University of Michigan/Michigan Medicine reported to HHS on 2018-06-25 a Theft affecting 871 individuals. Breached information located on Laptop. PHI involved names, dates of birth, diagnoses, lab results, medications, and treatment information. The entity notified HHS, individuals, and media, and implemented additional safeguards and staff retraining.