Skip to content

University of Kentucky

Disclosed Jun 18, 201016 years ago2,027 affectedConfirmed

Official notice

A laptop computer containing the protected health information (PHI) of approximately 2,027 individuals was stolen from the covered entity (CE), University of Kentucky, Department of Pediatrics. The information was part of the New Born Screening Program sent to that department by the state screening program. The types of PHI involved in the breach included demographic information, specifically, names, addresses, dates of birth, social security numbers, and other identifiers, and clinical information. As a result of OCR’s investigation the CE provided OCR with an updated status report of its encryption project that it had previously reported as one of its corrective measures. It also trained workforce members on encryption of computing devices and provided reminders to workforce members about its facility locking procedures. Additionally, the CE provided a report of its information security assessment with details of security gaps as evidence of its risk analysis, along with recommendations for remediation of the gaps identified in the assessment. The CE also improved physical safeguards. The CE provided documentation of compliance with the applicable notification provisions of the B

What is known

People affected2,027 (as reported to HHS)
DisclosedJun 18, 2010
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): University of Kentucky (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 18, 20102,027

Other breaches at University of Kentucky

BreachAffected
Disclosed Aug 5, 2021Aug 5, 20215 years agoUnknown
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of Kentucky

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.