- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 827
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 9, 2015, University of Colorado Health, the covered entity (CE) discovered that a nurse working in one of the CE’s network hospitals impermissibly accessed 827 individuals’ medical records between October 2014 and September 2015. The CE discovered the nurse’s impermissible accesses after an anonymous individual telephoned the CE’s privacy hotline regarding the nurse’s suspected conduct. To carry out these impermissible accesses, the nurse utilized the CE’s electronic health record (EHR) application. The CE provided breach notification to HHS, the media, and affected individuals. Based on the breach and OCR’s investigation, the CE sanctioned the nurse and terminated her access to the EHR. The CE also retrained nursing staff regarding use of the EHR in accordance with HIPAA. The CE has reported similar breaches to OCR, and OCR has consolidated the unresolved issues from this breach into a review along with related compliance concerns arising from the CE’s other breaches.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.