Back to the register

UMASSAmherst

ArchivedSubmitted 06/05/2013
State
MA
Covered entity type
Healthcare Provider
Individuals affected
1,670
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Desktop Computer
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

University of Massachusetts Amherst (UMass) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR). UMass will pay $650,000 and will adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program. UMass notified OCR that a workstation in its Center for Language, Speech, and Hearing (Center) was infected with a malware program which resulted in the impermissible disclosure of electronic protected health information (ePHI) of 1,670 individuals, including names, addresses, social security numbers, dates of birth, health insurance information, diagnoses and procedure codes. The University determined that the malware was a generic remote access Trojan that infiltrated their system, providing impermissible access to ePHI, because UMass did not have a firewall in place. OCR’s investigation indicated the following potential violations of the HIPAA Rules: • Failure to designate all of its health care components when hybridizing • Failure to implement technical security measures at the Center to guard against unauthorized access to ePHI transmitted over an electronic communications network by ensuring that firewalls were in place at the Center • Failure to conduct an accurate and thorough risk analysis prior to September 2015 • Impermissible disclosure of 1,670 individuals’ ePHI In addition to the monetary settlement, UMass has agreed to a corrective action plan that requires the organization to conduct an enterprise-wide risk analysis; develop and implement a risk management plan; revise its policies and procedures, and train its staff on these policies and procedures. The Resolution Agreement and Corrective Action Plan may be found on the OCR website at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/umass.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.