
University of Nebraska Medical Center Data Breach
The University of Nebraska Medical Center data breach affected at least 26,937 people after unauthorized access to UNMC's REDCap research application from September 2023 to February 2026.
REDCap supports research studies, quality improvement projects, and public health activities. UNMC said Nebraska Medicine's independently operated clinical systems were not affected by this incident.
What Happened in the UNMC REDCap Incident?UNMC learned in February 2026 that a vulnerability in REDCap could allow remote access to the application. The organization took the application offline and opened an investigation with outside cybersecurity consultants.
On February 18, 2026, the investigation determined that UNMC's REDCap instance had been accessed without authorization between September 20, 2023 and February 3, 2026. It found no evidence that personal information in the application was actually viewed.
What Information May Have Been Affected?According to UNMC's official notice, the information varied by project and person but may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and health information connected with research studies.
Health information could include visit dates, diagnoses, medications, laboratory results, imaging or procedure information, and questionnaire responses. A limited number of projects may also have stored Social Security numbers; not every field applied to every person.
How Many People Were Affected?The official U.S. Department of Health and Human Services breach portal reports 26,937 affected individuals. Because UNMC said its project review was ongoing and additional people could receive notices, the published figure should be treated as a lower bound.
What Should Affected People Do?Notice recipients should rely on the data scope in their own letters and review benefit statements and medical records for unfamiliar services, procedures, or charges. Any inaccurate entry should be verified directly with the relevant healthcare organization.
UNMC offered complimentary credit monitoring to people whose Social Security numbers were identified in REDCap. Unexpected messages using the name of the university or a research team should be verified independently, without using links contained in the message.