University of Missouri Health Care Data Breach
University of Missouri Health Care EMR Unauthorized Access
What happened in the University of Missouri Health Care data breach?
The University of Missouri Health Care data breach was reported on May 17, 2023 and affected 736 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
University of Missouri Health Care Breach Details
University of Missouri Health Care Data Breach Report
Incident Overview
University of Missouri Health Care experienced an unauthorized access incident affecting 736 individuals on or before May 17, 2023, when the breach was reported to the Missouri Attorney General and affected parties. The breach involved unauthorized access to electronic medical records (EMR) systems, compromising sensitive patient health information. This incident represents a significant security event for one of Missouri's major academic medical centers, requiring immediate notification to affected patients and regulatory authorities under HIPAA Breach Notification Rule requirements.
Discovery and Response Timeline
The University of Missouri Health Care organization discovered the unauthorized access to its electronic medical record systems and initiated a comprehensive investigation into the scope and nature of the breach. Upon discovery, the organization followed HIPAA-mandated breach notification procedures, conducting a thorough forensic investigation to determine which patient records were accessed without authorization. The submission date of May 17, 2023, indicates the organization met its obligation to notify affected individuals without unreasonable delay, typically within 60 days of discovery as required by federal regulations. The organization's response included securing affected systems, notifying law enforcement where appropriate, and implementing remedial measures to prevent similar incidents.
Technical Details and Breach Mechanism
The breach involved unauthorized access to the electronic medical record (EMR) system, which typically houses comprehensive patient health information including diagnoses, treatment plans, medications, and clinical notes. Unauthorized access incidents in EMR systems generally result from compromised credentials, inadequate access controls, insider threats, or exploitation of system vulnerabilities. The fact that this breach was categorized as "unauthorized access/disclosure" rather than a network intrusion or ransomware attack suggests the unauthorized party may have obtained legitimate system credentials or exploited access control weaknesses. Electronic medical record systems are high-value targets for threat actors due to the comprehensive nature of patient data they contain and the difficulty patients face in changing their health information compared to financial credentials.
Organizational Context
University of Missouri Health Care is a major academic medical center and health system serving Missouri and surrounding regions. As an academic medical center affiliated with the University of Missouri School of Medicine, the organization operates multiple facilities including hospitals, clinics, and specialty care centers. The health system serves a diverse patient population across central Missouri and maintains extensive electronic health records containing decades of accumulated patient information. The organization's size and scope as a regional academic medical center means it maintains particularly sensitive and comprehensive health information on its patient population, making it an attractive target for unauthorized access.
Patient Impact and Affected Information
Approximately 736 individuals had their protected health information potentially accessed without authorization. While the specific data elements exposed were not detailed in the breach submission, unauthorized access to EMR systems typically compromises multiple categories of sensitive health information. Patients affected by this breach should assume their medical records—including diagnoses, treatment history, medications, allergies, and potentially identifiers—may have been viewed by unauthorized parties. The notification process required the organization to contact all 736 affected individuals, providing details about the breach, the types of information potentially exposed, and recommended protective measures. This localized but significant breach affected a meaningful portion of the organization's patient population and required substantial notification and remediation efforts.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities like University of Missouri Health Care must notify affected individuals of breaches of unsecured protected health information without unreasonable delay and in no case later than 60 calendar days after discovery. The organization was also required to notify the Missouri Attorney General and, depending on the number of affected residents in other states, potentially other state attorneys general. Unauthorized access incidents represent approximately 20-25% of reported healthcare data breaches annually, making this a common threat vector in the healthcare industry. Unlike ransomware or theft incidents, unauthorized access breaches often involve either compromised employee credentials or exploitation of access control weaknesses, highlighting the importance of strong identity and access management controls in healthcare settings. The healthcare industry continues to experience significant pressure from threat actors seeking to monetize stolen health information through identity theft, medical fraud, or sale on dark web marketplaces.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the University of Missouri Health Care Breach
Monitor credit reports and financial accounts for suspicious activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized credit applications
Review medical records and explanation of benefits statements for unauthorized medical services or claims; contact healthcare providers immediately if you identify suspicious medical activity
Monitor for phishing emails or calls claiming to be from healthcare providers or insurance companies, as threat actors often use stolen health information for social engineering attacks
Consider enrolling in credit monitoring or identity theft protection services if offered by the organization; maintain copies of breach notification letters and documentation for potential future claims
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri