- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,298
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 26, 2017, UNC Health Care, the covered entity (CE), learned from a patient that between April 1, 2014, and February 17, 2017, the CE’s clinics had all prenatal patients complete a pregnancy home risk screening form to see if they were eligible for additional support services from Medicaid and sent all the forms to local county health departments, including for patients not participating in Medicaid. The breach affected the protected health information (PHI) of 1,298 individuals and included names, addresses, race, ethnicity, social security numbers, social behaviors, mental health statuses, sexually transmitted diseases, HIV status, drug and alcohol use, and medical diagnosis information related to pregnancy. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice and offered identity theft resolution services. The CE instructed the clinics to stop having non-Medicaid beneficiaries complete the screening forms, and the clinics purged their files of any non-Medicaid forms they had received. The CE retrained staff on the new procedure. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.