Back to the register

VCU Health System

ArchivedSubmitted 07/06/2018
State
VA
Covered entity type
Healthcare Provider
Individuals affected
4,686
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE) reported that from January 3, 2003, through May 10, 2018, a staff member accessed the protected health information (PHI) of 4,686 individuals without a legitimate business reason and that two other employees were aware, but did not report it. The types of PHI involved in the breach included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE increased safeguards by monitoring all user access and setting alerts for certain types of access. The CE sanctioned the employee who accessed the records without a business need along with the two employees who knew of the inappropriate access and failed to report it, which in this case included termination of employment for all three. OCR obtained assurances that the CE retrained its entire workforce on its policies and procedures.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.