Back to the register

Virginia Commonwealth University Health System

ArchivedSubmitted 03/10/2017
State
VA
Covered entity type
Healthcare Provider
Individuals affected
2,716
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Virginia Commonwealth University Health System, detected an unusual pattern of accessing electronic patient records from two different sources and confirmed that an employee of a community physician and an employee with a contracted vendor, acting independently, accessed patient records without a legitimate business need. The types of protected health information (PHI) potentially viewed included full names, home addresses, dates of birth, medical record numbers, providers, visit dates, health insurance information and diagnostic and treatment information. As a result of this incident, the respective employers sanctioned the employees. The CE obtained assurances from the former employees that any inappropriate accesses to the electronic medical records were viewed without malicious intent and no information was retained. The CE implemented additional administrative and technical safeguards, eliminated the option to browse records, and limited the information that was displayed as the result of a search to the minimum necessary. The CE provided breach notification to HHS, the media, and affected individuals. OCR obtained assurances that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.