University of Texas MD Anderson Cancer Center
Disclosed May 31, 20188 years ago1,266 affectedConfirmed
On May 3, 2018, the covered entity (CE), the University of Texas MD Anderson Cancer Center, discovered that a workforce member erroneously sent a research recruitment email to 1,266 individuals in a manner that allowed them to be seen by the other email recipients. The CE determined that some emails were undeliverable and it stopped others; however, it is believed 599 emails were delivered. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach incident, the CE implemented a new technical safeguard and re-educated workforce members concerning policies, procedures, and tips to prevent impermissible disclosures of PHI involving email. The CE also sanctioned the involved workforce member. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,266 (as reported to HHS) |
|---|---|
| Disclosed | May 31, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): University of Texas MD Anderson Cancer Center (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 31, 2018 | 1,266 |
Other breaches at University of Texas MD Anderson Cancer Center
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Aug 17, 2012Aug 17, 201214 years agoLost or stolen device | Aug 17, 201214 years ago | Lost or stolen device | Healthcare | Confirmed | 29K |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about University of Texas MD Anderson Cancer Center