OU Medicine, the Oklahoma-based health system also known as OU Health, has reported a data breach affecting 854 people. A former employee accessed patient records without a business reason between December 30, 2025, and June 7, 2026.
OU Medicine’s Data Breach Investigation
OU Medicine, Inc. is a healthcare provider based in Oklahoma and part of OU Health, the University of Oklahoma’s academic health system. In September 2026, it posted a public notice describing a data security incident involving one of its own employees rather than an outside hacker.
According to the notice, OU Medicine became aware on or about June 7, 2026, of an employee’s unusual pattern of accessing patient health information. It opened an investigation and worked with outside cybersecurity professionals. After reviewing access audit logs, it confirmed on July 20, 2026, that the employee had accessed some patient information without a legitimate business reason. The notice says the employee has since been terminated.
The access took place over roughly six months, from approximately December 30, 2025, through June 7, 2026. OU Medicine reports that it has no indication of fraud resulting from the incident. It also says not every type of information was affected for every individual, so what any one patient’s record included may differ.
OU Medicine reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on September 18, 2026. The federal breach portal lists 854 individuals affected, with the type of breach recorded as unauthorized access or disclosure and the location as an electronic medical record and a network server. The company began notifying affected individuals on or about September 20, 2026.
Insider access cases differ from ransomware or hacking incidents. The concern is not that data was locked or sold by a criminal group, but that someone with legitimate system credentials viewed records they had no work-related reason to open. Healthcare organizations rely on audit logs to spot this kind of pattern, and in this case the logs are what allowed OU Medicine to confirm the scope of the access.
Medical information can be sensitive in ways a password or card number is not. Diagnoses, medications and lab results cannot be changed once they are exposed, and they can be misused for medical identity theft or targeted scams. Patients who receive a notice should read it carefully and keep a copy for their records.
If you were treated at an OU Medicine facility and are unsure whether you are among the people affected, watch your mail for a notification letter. The notice lists a dedicated call center for questions and says the response line is available for 90 days from the date of the letter.
When Did This Breach Occur?
OU Medicine says it became aware of unusual access on or about June 7, 2026, and confirmed on July 20, 2026, that a now-terminated employee had accessed patient information without a legitimate business reason between approximately December 30, 2025, and June 7, 2026. It reported the incident to federal regulators on September 18, 2026, and began notifying individuals on or about September 20, 2026.
What Information Was Breached?
OU Medicine reports that the information involved included full name, email address, phone number, patient photo, medical record number, gender, age, treatment information, date of admission, medication information, lab results, imaging, diagnosis and vitals information. Not all information was affected for every individual, and no Social Security numbers or financial account details were listed in the notice.
What You Can Do
If you were an OU Medicine patient, consider these steps to protect yourself:
- Read any notification letter from OU Medicine carefully and keep it, along with the date you received it.
- Review the explanation of benefits statements from your health insurer and ask your insurer or provider about any service you do not recognize.
- Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion, and check your credit reports for free at annualcreditreport.com.
- Be cautious of emails, texts or calls that mention your care or your medical details. Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against OU Medicine
If you received a notice from OU Medicine, or believe your medical information was viewed without authorization, you may have legal options. Healthcare providers are expected to protect patient records and to monitor who can see them, and a class action can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.