Back to the register

UNC Health Care

ArchivedSubmitted 03/20/2017
State
NC
Covered entity type
Healthcare Provider
Individuals affected
1,298
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On January 26, 2017, UNC Health Care, the covered entity (CE), learned from a patient that between April 1, 2014, and February 17, 2017, the CE’s clinics had all prenatal patients complete a pregnancy home risk screening form to see if they were eligible for additional support services from Medicaid and sent all the forms to local county health departments, including for patients not participating in Medicaid. The breach affected the protected health information (PHI) of 1,298 individuals and included names, addresses, race, ethnicity, social security numbers, social behaviors, mental health statuses, sexually transmitted diseases, HIV status, drug and alcohol use, and medical diagnosis information related to pregnancy. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice and offered identity theft resolution services. The CE instructed the clinics to stop having non-Medicaid beneficiaries complete the screening forms, and the clinics purged their files of any non-Medicaid forms they had received. The CE retrained staff on the new procedure. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.