Skip to content

University of Iowa Hospitals & Clinics

Disclosed Jun 25, 20197 years ago950 affectedConfirmed

Official notice

The covered entity (CE), the University of Iowa Hospitals and Clinics, reported that an employee emailed the protected health information (PHI) of 950 individuals to other members of a research study without authorization. The PHI involved included names, email addresses, and diagnoses/conditions. The CE notified HHS, affected individuals, the media, and established a toll free number for questions or concerns. In its mitigation efforts, the CE implemented additional administrative safeguards and retrained its staff on privacy protections. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected950 (as reported to HHS)
DisclosedJun 25, 2019
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 25, 2019950

Other breaches at University of Iowa Hospitals & Clinics

BreachAffected
Disclosed Jun 22, 2017Jun 22, 20179 years agoInsider5,292
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of Iowa Hospitals & Clinics

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.