Skip to content

University of Wisconsin Hospitals and Clinics Authority

Disclosed Sep 30, 20169 years ago6,923 affectedConfirmed

Official notice

The covered entity (CE), University of Wisconsin and Clinics Authority, reported that a survey was erroneously mailed to family members of 6,923 patients rather than to the patients directly. The breach occurred because of formatting problems sent in a data file to the CE’s business associate (BA). The PHI included patients’ names and the names of patients’ healthcare providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE initiated an internal investigation and directed appropriate staff and the BA (collectively, the “Root Cause Analysis Team”) to determine the root cause and severity of the breach. As a result of the root cause analysis, the CE developed an action plan to prevent similar disclosures, revised and redesigned processes for providing patient survey information, and trained pertinent staff on the new processes. OCR obtained documented assurances that the CE implemented these corrective actions. During the investigation, OCR reviewed copies of the CE’s policies and procedures for uses and disclosures and the safeguarding of PHI.

What is known

People affected6,923 (as reported to HHS)
DisclosedSep 30, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 30, 20166,923

Other breaches at University of Wisconsin Hospitals and Clinics Authority

BreachAffected
Disclosed Mar 5, 2024Mar 5, 20242 years agoHacking86K
Disclosed Jun 18, 2021Jun 18, 20215 years agoHacking4,563
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of Wisconsin Hospitals and Clinics Authority

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.