University Hospital
ent_f66404ed3e4806cd774cc910
Disclosures
10
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
39,207
nationwide · HHS OCR NJ
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University Hospital
- Normalized
- university hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- uhnj.org
Disclosure history (10)newest first
- NEW JERSEYHHS OCRas victim2021-11-05
University Hospital (NJ) reported to HHS on 2021-11-05 an Unauthorized Access/Disclosure affecting 10,067 individuals. A workforce member impermissibly accessed PHI including names, addresses, dates of birth, SSNs, health insurance information, diagnoses, and other treatment information stored in Electronic Medical Records. The CE sanctioned the responsible workforce member and retrained staff.
- New Hampshire State AGas victim2021-11-03
University Hospital notified the NH Attorney General of an insider threat incident involving a former employee who accessed and provided patient data (PII, PHI, SSN) to unauthorized parties between Jan 1, 2016 and Dec 31, 2017. The breach was discovered on Aug 24, 2021. Notifications were mailed on Oct 8, 2021, offering credit monitoring. A criminal investigation is ongoing.
- Massachusetts State AGas victim2021-11-03
University Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-11-03. 10 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2021-11-03
University Hospital reported an insider wrongdoing incident occurring between 01/01/2016 and 12/31/2017, discovered on 08/24/2021. The breach compromised names and Social Security Numbers of 9,329 individuals, including 2 Maine residents. Notification was sent on 10/08/2021, offering one year of credit monitoring via Experian.
- Montana State AGas victim2021-10-08
University Hospital notified Montana residents that a former employee with authorized access misused patient information between Jan 1, 2016 and Dec 31, 2017. Data included names, DOBs, SSNs, insurance info, and clinical records. A criminal investigation is ongoing. The hospital offered one year of Experian IdentityWorks.
- NEW JERSEYHHS OCRas victim2021-10-08
University Hospital reported to HHS on 2021-10-08 a Unauthorized Access/Disclosure affecting 9,329 individuals. Breached information located on Electronic Medical Record. A workforce member impermissibly accessed PHI including names, SSNs, and diagnoses.
- Illinois State AGas victim2021-01-01
UNIVERSITY HOSPITAL filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-067). The register records the breach as discovered on September 14, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
UNIVERSITY HOSPITAL filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-440). The register records the breach as discovered on August 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW JERSEYHHS OCRas victim2020-11-13
University Hopsital reported to HHS on 2020-11-13 a Hacking/IT Incident affecting 39207 individuals. Breached information located on Network Server. PHI included names, addresses, DOB, SSN, driver's license, passport, and health insurance info.
- Montana State AGas victim2020-11-12
University Hospital notified Montana residents of a cyber incident where an unauthorized individual accessed patient systems containing PII, PHI, and financial data. Access occurred Sept 10, 2020; detected Sept 14, 2020. UH engaged forensic experts and law enforcement, enhanced security protocols, and offered one year of credit monitoring.