All Breaches
September 20, 2023 Verified Healthcare

University of Nebraska Medical Center Data Breach

The University of Nebraska Medical Center data breach affected at least 26,937 people after unauthorized access to UNMC's REDCap research application from September 2023 to February 2026.

REDCap supports research studies, quality improvement projects, and public health activities. UNMC said Nebraska Medicine's independently operated clinical systems were not affected by this incident.

What Happened in the UNMC REDCap Incident?

UNMC learned in February 2026 that a vulnerability in REDCap could allow remote access to the application. The organization took the application offline and opened an investigation with outside cybersecurity consultants.

On February 18, 2026, the investigation determined that UNMC's REDCap instance had been accessed without authorization between September 20, 2023 and February 3, 2026. It found no evidence that personal information in the application was actually viewed.

What Information May Have Been Affected?

According to UNMC's official notice, the information varied by project and person but may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and health information connected with research studies.

Health information could include visit dates, diagnoses, medications, laboratory results, imaging or procedure information, and questionnaire responses. A limited number of projects may also have stored Social Security numbers; not every field applied to every person.

How Many People Were Affected?

The official U.S. Department of Health and Human Services breach portal reports 26,937 affected individuals. Because UNMC said its project review was ongoing and additional people could receive notices, the published figure should be treated as a lower bound.

What Should Affected People Do?

Notice recipients should rely on the data scope in their own letters and review benefit statements and medical records for unfamiliar services, procedures, or charges. Any inaccurate entry should be verified directly with the relevant healthcare organization.

UNMC offered complimentary credit monitoring to people whose Social Security numbers were identified in REDCap. Unexpected messages using the name of the university or a research team should be verified independently, without using links contained in the message.

26.9 Thousand
Affected People
11
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

11
Names
Dates of birth
Physical addresses
Phone numbers
Email addresses
Medical record numbers
Social security numbers
Diagnoses
Prescription information
Treatment information
Medical information

Additional Information

Added DateJuly 29, 2026
Breach DateSeptember 20, 2023
Domainunmc.edu