The covered entity (CE), UT Southwestern Medical Center, reported that multiple employees impermissibly disclosed the protected health information (PHI) of 43,048 individuals using a calendar app. The PHI involved included names, dates of birth, social security numbers, financial and claims information, diagnoses, conditions, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE implemented additional technical safeguards and HIPAA training.
2026-09-25 · records: 43048 to 98437 · backfill source
2026-09-25 · disclosed: 2024-03-27 to 2023-07-24 · backfill source
2026-09-25 · disclosed: 2024-09-24 to 2024-03-27 · backfill source
2026-09-25 · disclosed: 2024-12-09 to 2024-09-24 · backfill source
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · records_basis: organization to hhs · backfill source
2026-09-25 · records: 433 to 43048 · backfill source
2026-09-25 · disclosed: 2026-02-13 to 2024-12-09 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), UT Southwestern Medical Center, reported that multiple employees impermissibly disclosed the protected health information (PHI) of 43,048 individuals using a calendar app. The PHI involved included names, dates of b · backfill source