Skip to content

University of Michigan/Michigan Medicine

Disclosed Oct 16, 20205 years ago1,062 affectedConfirmed

Official notice

The covered entity (CE), University of Michigan/Michigan Medicine, reported that an employee inadvertently sent an email that contained the electronic protected health information (ePHI) of 1,062 individuals without using the bind carbon copy function. The ePHI involved included names, email addresses, and diagnoses/conditions. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the responsible employee and retrained its workforce on email security. OCR provided technical assistance to the CE regarding the HIPAA Privacy and Security Rules.

What is known

People affected1,062 (as reported to HHS)
DisclosedOct 16, 2020
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 16, 20201,062

Other breaches at University of Michigan/Michigan Medicine

BreachAffected
Disclosed Jul 19, 2024Jul 19, 20242 years agoInsider58K
Disclosed Mar 3, 2022Mar 3, 20224 years agoHacking34K
Disclosed Jun 25, 2018Jun 25, 20188 years agoHacking5,466
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of Michigan/Michigan Medicine

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.