VCU Health System
Disclosed Jul 6, 20188 years ago4,686 affectedConfirmed
The covered entity (CE) reported that from January 3, 2003, through May 10, 2018, a staff member accessed the protected health information (PHI) of 4,686 individuals without a legitimate business reason and that two other employees were aware, but did not report it. The types of PHI involved in the breach included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE increased safeguards by monitoring all user access and setting alerts for certain types of access. The CE sanctioned the employee who accessed the records without a business need along with the two employees who knew of the inappropriate access and failed to report it, which in this case included termination of employment for all three. OCR obtained assurances that the CE retrained its entire workforce on its policies and procedures.
What is known
| People affected | 4,686 (as reported to HHS) |
|---|---|
| Disclosed | Jul 6, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): VCU Health System (Healthcare Provider, VA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 6, 2018 | 4,686 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.