Skip to content

UT Southwestern Medical Center

Disclosed Aug 13, 20206 years ago15,535 affectedConfirmed

Official notice

The covered entity (CE), UT Southwestern Medical Center, reported that an employee sent an email to its business associate (BA) without a business associate agreement (BAA) in place. This breach affected the electronic protected health information (ePHI) of approximately 3,640 individuals. The ePHI involved included names and email addresses. The CE notified HHS and affected individuals. In response to the breach, the CE strengthened its administrative safeguards and retrained its workforce members on the importance of having a BAA in place prior to disclosing ePHI. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected15,535 (as reported to HHS)
DisclosedAug 13, 2020
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalAug 13, 202015,535
HHS archivetotalFeb 5, 20213,640

Other breaches at UT Southwestern Medical Center

BreachAffected
Disclosed Jul 24, 2023Jul 24, 20233 years agoInsider98K
History of this record
  • 2026-09-25 · records: 3640 to 15535 · backfill source
  • 2026-09-25 · disclosed: 2021-02-05 to 2020-08-13 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UT Southwestern Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.