Back to the register
University of Wisconsin Hospitals and Clinics Authority
ArchivedSubmitted 09/30/2016
- State
- WI
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,923
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), University of Wisconsin and Clinics Authority, reported that a survey was erroneously mailed to family members of 6,923 patients rather than to the patients directly. The breach occurred because of formatting problems sent in a data file to the CE’s business associate (BA). The PHI included patients’ names and the names of patients’ healthcare providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE initiated an internal investigation and directed appropriate staff and the BA (collectively, the “Root Cause Analysis Team”) to determine the root cause and severity of the breach. As a result of the root cause analysis, the CE developed an action plan to prevent similar disclosures, revised and redesigned processes for providing patient survey information, and trained pertinent staff on the new processes. OCR obtained documented assurances that the CE implemented these corrective actions. During the investigation, OCR reviewed copies of the CE’s policies and procedures for uses and disclosures and the safeguarding of PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.