Skip to content

Virginia Commonwealth University Health System

Disclosed Mar 10, 20179 years ago2,716 affectedConfirmed

Official notice

The covered entity (CE), Virginia Commonwealth University Health System, detected an unusual pattern of accessing electronic patient records from two different sources and confirmed that an employee of a community physician and an employee with a contracted vendor, acting independently, accessed patient records without a legitimate business need. The types of protected health information (PHI) potentially viewed included full names, home addresses, dates of birth, medical record numbers, providers, visit dates, health insurance information and diagnostic and treatment information. As a result of this incident, the respective employers sanctioned the employees. The CE obtained assurances from the former employees that any inappropriate accesses to the electronic medical records were viewed without malicious intent and no information was retained. The CE implemented additional administrative and technical safeguards, eliminated the option to browse records, and limited the information that was displayed as the result of a search to the minimum necessary. The CE provided breach notification to HHS, the media, and affected individuals. OCR obtained assurances that the CE implemented th

What is known

People affected2,716 (as reported to HHS)
DisclosedMar 10, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 10, 20172,716

Other breaches at Virginia Commonwealth University Health System

BreachAffected
Disclosed May 27, 2022May 27, 20224 years agoInsider4,441
Disclosed Mar 31, 2020Mar 31, 20206 years ago2,131
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Virginia Commonwealth University Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.