Skip to content

UofL Health

Disclosed Aug 18, 20233 years ago8,175 affectedConfirmed

Official notice

The covered entity (CE), UofL Health, reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 8,175 individuals. The PHI involved included names, dates of birth, drivers’ license and Social Security numbers, addresses, and treatment information. In response to the breach, the CE and BA provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained to protect and secure PHI.

What is known

People affected8,175 (as reported by the organization)
DisclosedAug 18, 2023
HappenedMay 30, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2023 data breach report: UofL Healthin.gov · Official notice
HHS OCR breach report (archive, resolved): UofL Health (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INAug 18, 2023277
HHS archivetotalAug 18, 20238,175

Other breaches at UofL Health

BreachAffected
Disclosed Jun 7, 2021Jun 7, 20215 years agoInsider42K
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), UofL Health, reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 8,175 individuals. The PHI involved included names, dates of birth, drivers’ li · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about UofL Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.