Back to the register

University of Wisconsin Hospitals and Clinics Authority

ArchivedSubmitted 09/30/2016
State
WI
Covered entity type
Healthcare Provider
Individuals affected
6,923
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), University of Wisconsin and Clinics Authority, reported that a survey was erroneously mailed to family members of 6,923 patients rather than to the patients directly. The breach occurred because of formatting problems sent in a data file to the CE’s business associate (BA). The PHI included patients’ names and the names of patients’ healthcare providers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE initiated an internal investigation and directed appropriate staff and the BA (collectively, the “Root Cause Analysis Team”) to determine the root cause and severity of the breach. As a result of the root cause analysis, the CE developed an action plan to prevent similar disclosures, revised and redesigned processes for providing patient survey information, and trained pertinent staff on the new processes. OCR obtained documented assurances that the CE implemented these corrective actions. During the investigation, OCR reviewed copies of the CE’s policies and procedures for uses and disclosures and the safeguarding of PHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.