- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,670
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
University of Massachusetts Amherst (UMass) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR). UMass will pay $650,000 and will adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program.
UMass notified OCR that a workstation in its Center for Language, Speech, and Hearing (Center) was infected with a malware program which resulted in the impermissible disclosure of electronic protected health information (ePHI) of 1,670 individuals, including names, addresses, social security numbers, dates of birth, health insurance information, diagnoses and procedure codes. The University determined that the malware was a generic remote access Trojan that infiltrated their system, providing impermissible access to ePHI, because UMass did not have a firewall in place.
OCR’s investigation indicated the following potential violations of the HIPAA Rules:
• Failure to designate all of its health care components when hybridizing
• Failure to implement technical security measures at the Center to guard against unauthorized access to ePHI transmitted over an electronic communications network by ensuring that firewalls were in place at the Center
• Failure to conduct an accurate and thorough risk analysis prior to September 2015
• Impermissible disclosure of 1,670 individuals’ ePHI
In addition to the monetary settlement, UMass has agreed to a corrective action plan that requires the organization to conduct an enterprise-wide risk analysis; develop and implement a risk management plan; revise its policies and procedures, and train its staff on these policies and procedures. The Resolution Agreement and Corrective Action Plan may be found on the OCR website at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/umass.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.