Skip to content

UNC Health Care

Disclosed Mar 20, 20179 years ago1,298 affectedConfirmed

Official notice

On January 26, 2017, UNC Health Care, the covered entity (CE), learned from a patient that between April 1, 2014, and February 17, 2017, the CE’s clinics had all prenatal patients complete a pregnancy home risk screening form to see if they were eligible for additional support services from Medicaid and sent all the forms to local county health departments, including for patients not participating in Medicaid. The breach affected the protected health information (PHI) of 1,298 individuals and included names, addresses, race, ethnicity, social security numbers, social behaviors, mental health statuses, sexually transmitted diseases, HIV status, drug and alcohol use, and medical diagnosis information related to pregnancy. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice and offered identity theft resolution services. The CE instructed the clinics to stop having non-Medicaid beneficiaries complete the screening forms, and the clinics purged their files of any non-Medicaid forms they had received. The CE retrained staff on the new procedure. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected1,298 (as reported to HHS)
DisclosedMar 20, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): UNC Health Care (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 20, 20171,298
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UNC Health Care

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.