Skip to content

University of Texas MD Anderson Cancer Center

Disclosed Aug 17, 201214 years ago29,021 affectedConfirmed

Official notice

The covered entity (CE), The University of Texas MD Anderson Cancer Center, reported a breach of electronic protected health information (ePHI) due to the loss of an unencrypted thumb drive that contained the ePHI of 3,598 individuals. The ePHI involved included names, birthdates, diagnoses, lab results, medications prescribed, and other treatment information. Upon the completion of its investigation, OCR sought resolution of potential violations of the HIPAA Rules for failure to implement encryption and decryption and impermissible disclosure of ePHI. When informal resolution was not successful, OCR proceeded with formal enforcement. An administrative law judge and the Departmental Appeals Board (DAB) ruled in OCR’s favor and imposed a civil money penalty (CMP); however, the U.S. 5th Circuit Court of appeals vacated the CMP and remanded this case to the DAB for further proceedings consistent with their opinion. The DAB dismissed the case.

What is known

People affected29,021 (as reported to HHS)
DisclosedAug 17, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalAug 17, 20122,264
HHS archivetotalJan 24, 201329,021
HHS archivetotalJan 31, 20143,598

Other breaches at University of Texas MD Anderson Cancer Center

BreachAffected
Disclosed May 31, 2018May 31, 20188 years agoInsider1,266
History of this record
  • 2026-09-25 · disclosed: 2013-01-24 to 2012-08-17 · backfill source
  • 2026-09-25 · records: 3598 to 29021 · backfill source
  • 2026-09-25 · disclosed: 2014-01-31 to 2013-01-24 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of Texas MD Anderson Cancer Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.