Back to the register
University of Louisville Research Foundation, Inc., DBA The Kidney Disease Program
ArchivedSubmitted 06/01/2010
- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 708
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An outside computer’s unique numerical code (Internet Protocol address) accessed the covered entity’s (CE) website which contained a database containing the protected health information of 708 patients. The types of PHI involved in the breach included names, social security numbers, and treatment information. The CE provided breach notification to HHS and affected individuals. Following the breach, the CE disabled the website containing the breached PHI. As a result of OCR’s investigation, the CE removed social security numbers from its site, added a time out feature, retrained staff, and completed a risk assessment.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.