Back to the register

UC Health, LLC

ArchivedSubmitted 11/14/2015
State
OH
Covered entity type
Healthcare Provider
Individuals affected
1,064
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On September 16, 2015, the covered entity (CE), UC Health, discovered a breach of electronic protected health information (ePHI) when it received a security malware alert associated with the domain name of “uchelath.com”, which was similar in spelling to UC’s authorized domain name of “uchealth.com”. The breach affected approximately 1,064 individuals and the types of ePHI involved included patients’ names, addresses, phone numbers, medical record number, diagnoses, procedures, admission and discharge dates, visit dates, surgery dates, birthdates, physicians’ name, account numbers, and one email included a patient’s social security number. Following the breach, the CE blocked all Web traffic to and from the suspicious domain. The CE also analyzed emails that may have been sent from the suspicious domain to the CE. The CE provided breach notification to HHS, affected individuals, and the media. It also contacted the FBI about the breach. OCR obtained documented assurances that the CE implemented the corrective actions steps noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.