top of page
KDG OPFC Great Plains Web Banner Ad-1 V1.jpg

OU Health Data Breach Exposed Patient Medical Records

Writer: mike33692
mike33692
7 hours ago
4 min read
Blue computer motherboard with a glowing DATA BREACH warning, binary code overlays, and a dark cybercrime-themed background

OU Health Data Breach Exposed Patient Medical Records for More Than Five Months

OU Health is notifying patients after discovering that a former employee accessed private medical information without a legitimate business reason for more than five months. The unauthorized activity occurred between approximately December 30, 2025, and June 7, 2026, and potentially involved treatment information, medical record numbers, lab results, imaging and diagnoses.

The OU Health data breach was discovered after the health system identified an unusual pattern of employee access on June 7. OU Health launched an investigation with outside cybersecurity professionals and confirmed on July 20 that the employee had accessed patient information without authorization. The employee involved has since been terminated.

OU Health Data Breach May Include Medical Records, Lab Results and Diagnoses

OU Health said the information potentially accessed varies from patient to patient, meaning not every affected person had every category of information exposed.

According to OU Health's official notice regarding the data security incident, potentially affected information included full names, email addresses, phone numbers, patient photographs, medical record numbers, gender and age.

More sensitive medical information may also have been accessed, including treatment information, admission dates, medications, laboratory results, medical imaging, diagnoses and vital information.

OU Health said it became aware of the employee's unusual access pattern on or about June 7 and immediately began investigating.

A review of access audit logs determined on July 20 that the employee had accessed information about patients and the medical services they received without a legitimate business reason.

OU Health has not publicly identified the former employee.

The health system also said it currently has no indication that fraud has occurred because of the incident.

Patient notifications began around September 20, with letters being sent to individuals whose information was included in records that may have been accessed.

The notice does not state that every OU Health patient was affected, and patients who receive a notification should review it carefully to determine what information may have been involved in their individual case.

Patients Should Watch Medical Records and Insurance Statements for Suspicious Activity

A medical data breach can create risks beyond traditional financial identity theft because exposed information may contain details about a person's health care history.

OU Health is advising affected patients to monitor their information and has provided guidance for protecting both financial and medical records.

Patients should review health insurance explanation of benefits statements and watch for treatments, providers or services they do not recognize. They can also ask their insurance company for a year-to-date report showing services paid on their behalf.

Anyone who discovers unfamiliar medical activity should contact the insurer or health care provider associated with the transaction.

Affected patients can also monitor their credit reports and consider placing a fraud alert or security freeze with the major credit reporting agencies.

Federal law establishes specific notification requirements when protected health information is compromised. The U.S. Department of Health and Human Services explains its HIPAA breach notification requirements, which require covered health care organizations to notify affected individuals following qualifying breaches of unsecured protected health information.

Patients should also be particularly cautious about phishing emails, scam phone calls and suspicious text messages that appear to reference their health care.

A caller possessing someone's name or medical information should not automatically be assumed to represent OU Health, an insurance company or another legitimate health organization.

Patients should avoid providing passwords, banking information, Social Security numbers or other sensitive information in response to an unsolicited contact and instead independently contact the organization using a verified phone number or website.

OU Health Opens Dedicated Call Center for Affected Patients

OU Health has established a dedicated confidential call center for people with questions about the incident.

Patients can call 888-619-1140 between 9 a.m. and 9 p.m. Eastern time Monday through Friday, excluding holidays. OU Health said the response line will remain available for 90 days from the date of the notification letter.

Patients who believe their health information privacy rights have been violated also have the option of filing a complaint with the federal government.

The HHS Office for Civil Rights accepts health information privacy and security complaints involving organizations covered by federal HIPAA privacy, security and breach notification requirements.

Federal guidance generally requires complaints to be filed within 180 days of when a person knew about the alleged violation, although that period can be extended for good cause.

For patients receiving an OU Health notification, the most immediate steps are to read the letter carefully, monitor medical and insurance records, watch for suspicious communications and review financial accounts and credit reports for unfamiliar activity.

OU Health said it continues to evaluate and modify its privacy and security practices following the incident.

The OU Health data breach involved unauthorized access by a former employee over a period spanning more than five months, making continued monitoring especially important for patients who receive notification that their medical information may have been involved.

Comments


bottom of page