- State
- VA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,716
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Virginia Commonwealth University Health System, detected an unusual pattern of accessing electronic patient records from two different sources and confirmed that an employee of a community physician and an employee with a contracted vendor, acting independently, accessed patient records without a legitimate business need. The types of protected health information (PHI) potentially viewed included full names, home addresses, dates of birth, medical record numbers, providers, visit dates, health insurance information and diagnostic and treatment information. As a result of this incident, the respective employers sanctioned the employees. The CE obtained assurances from the former employees that any inappropriate accesses to the electronic medical records were viewed without malicious intent and no information was retained. The CE implemented additional administrative and technical safeguards, eliminated the option to browse records, and limited the information that was displayed as the result of a search to the minimum necessary. The CE provided breach notification to HHS, the media, and affected individuals. OCR obtained assurances that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.