UC Health, LLC (OH) reported to HHS OCR on 2015-11-14 an Unauthorized Access/Disclosure breach affecting 1,064 individuals. Discovered on September 16, 2015, after a malware alert flagged the spoofed domain 'uchelath.com' mimicking the legitimate 'uchealth.com'. Exposed ePHI included names, addresses, phone numbers, medical record numbers, diagnoses, procedures, dates, birthdates, account numbers, and one SSN. Breached information was located in Email. CE blocked suspicious domain traffic, notified HHS, affected individuals, media, and the FBI. OCR obtained documented assurances of corrective actions.
Affected (this filing): 1,064