- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,598
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), The University of Texas MD Anderson Cancer Center, reported a breach of electronic protected health information (ePHI) due to the loss of an unencrypted thumb drive that contained the ePHI of 3,598 individuals. The ePHI involved included names, birthdates, diagnoses, lab results, medications prescribed, and other treatment information. Upon the completion of its investigation, OCR sought resolution of potential violations of the HIPAA Rules for failure to implement encryption and decryption and impermissible disclosure of ePHI. When informal resolution was not successful, OCR proceeded with formal enforcement. An administrative law judge and the Departmental Appeals Board (DAB) ruled in OCR’s favor and imposed a civil money penalty (CMP); however, the U.S. 5th Circuit Court of appeals vacated the CMP and remanded this case to the DAB for further proceedings consistent with their opinion. The DAB dismissed the case.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.