Skip to content

UMASSAmherst

Disclosed Jun 5, 201313 years ago1,670 affectedConfirmed

Official notice

University of Massachusetts Amherst (UMass) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR). UMass will pay $650,000 and will adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program. UMass notified OCR that a workstation in its Center for Language, Speech, and Hearing (Center) was infected with a malware program which resulted in the impermissible disclosure of electronic protected health information (ePHI) of 1,670 individuals, including names, addresses, social security numbers, dates of birth, health insurance information, diagnoses and procedure codes. The University determined that the malware was a generic remote access Trojan that infiltrated their system, providing impermissible access to ePHI, because UMass did not have a firewall in place. OCR’s investigation indicated the following potential violations of the HIPAA Rules: • Failure to designate all of its health care components when hybridizing • Failure to implement technical security measures at th

What is known

People affected1,670 (as reported to HHS)
DisclosedJun 5, 2013
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): UMASSAmherst (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 5, 20131,670
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UMASSAmherst

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.