Skip to content

UC Health

Disclosed Nov 14, 201510 years ago1,064 affectedConfirmed

Official notice

On September 16, 2015, the covered entity (CE), UC Health, discovered a breach of electronic protected health information (ePHI) when it received a security malware alert associated with the domain name of “uchelath.com”, which was similar in spelling to UC’s authorized domain name of “uchealth.com”. The breach affected approximately 1,064 individuals and the types of ePHI involved included patients’ names, addresses, phone numbers, medical record number, diagnoses, procedures, admission and discharge dates, visit dates, surgery dates, birthdates, physicians’ name, account numbers, and one email included a patient’s social security number. Following the breach, the CE blocked all Web traffic to and from the suspicious domain. The CE also analyzed emails that may have been sent from the suspicious domain to the CE. The CE provided breach notification to HHS, affected individuals, and the media. It also contacted the FBI about the breach. OCR obtained documented assurances that the CE implemented the corrective actions steps noted above.

What is known

People affected1,064 (as reported to HHS)
DisclosedNov 14, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): UC Health (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 14, 20151,064

Other breaches at UC Health

BreachAffected
Disclosed Sep 4, 2019Sep 4, 20197 years agoHacking95K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UC Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.