Were you recently affected by a data breach?

OU Medicine Data Breach

OU Medicine, an Oklahoma health system, reported that a former employee accessed patient records without authorization from December 30, 2025, to June 7, 2026. HHS lists 854 people affected.

OU Medicine
Date of Breach: December 30, 2025 to June 7, 2026
CAU logo

Who was affected:

Clients of OU Medicine

Impacted Data:

Full name, email address, phone number, patient photo, medical record number, gender, age, treatment information, date of admission, medication information, lab results, imaging, diagnosis and vitals information. Not all information was affected for every individual.

OU Medicine, the Oklahoma-based health system also known as OU Health, has reported a data breach affecting 854 people. A former employee accessed patient records without a business reason between December 30, 2025, and June 7, 2026.

OU Medicine’s Data Breach Investigation

OU Medicine, Inc. is a healthcare provider based in Oklahoma and part of OU Health, the University of Oklahoma’s academic health system. In September 2026, it posted a public notice describing a data security incident involving one of its own employees rather than an outside hacker.

According to the notice, OU Medicine became aware on or about June 7, 2026, of an employee’s unusual pattern of accessing patient health information. It opened an investigation and worked with outside cybersecurity professionals. After reviewing access audit logs, it confirmed on July 20, 2026, that the employee had accessed some patient information without a legitimate business reason. The notice says the employee has since been terminated.

The access took place over roughly six months, from approximately December 30, 2025, through June 7, 2026. OU Medicine reports that it has no indication of fraud resulting from the incident. It also says not every type of information was affected for every individual, so what any one patient’s record included may differ.

OU Medicine reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on September 18, 2026. The federal breach portal lists 854 individuals affected, with the type of breach recorded as unauthorized access or disclosure and the location as an electronic medical record and a network server. The company began notifying affected individuals on or about September 20, 2026.

Insider access cases differ from ransomware or hacking incidents. The concern is not that data was locked or sold by a criminal group, but that someone with legitimate system credentials viewed records they had no work-related reason to open. Healthcare organizations rely on audit logs to spot this kind of pattern, and in this case the logs are what allowed OU Medicine to confirm the scope of the access.

Medical information can be sensitive in ways a password or card number is not. Diagnoses, medications and lab results cannot be changed once they are exposed, and they can be misused for medical identity theft or targeted scams. Patients who receive a notice should read it carefully and keep a copy for their records.

If you were treated at an OU Medicine facility and are unsure whether you are among the people affected, watch your mail for a notification letter. The notice lists a dedicated call center for questions and says the response line is available for 90 days from the date of the letter.

When Did This Breach Occur?

OU Medicine says it became aware of unusual access on or about June 7, 2026, and confirmed on July 20, 2026, that a now-terminated employee had accessed patient information without a legitimate business reason between approximately December 30, 2025, and June 7, 2026. It reported the incident to federal regulators on September 18, 2026, and began notifying individuals on or about September 20, 2026.

What Information Was Breached?

OU Medicine reports that the information involved included full name, email address, phone number, patient photo, medical record number, gender, age, treatment information, date of admission, medication information, lab results, imaging, diagnosis and vitals information. Not all information was affected for every individual, and no Social Security numbers or financial account details were listed in the notice.

What You Can Do

If you were an OU Medicine patient, consider these steps to protect yourself:

  • Read any notification letter from OU Medicine carefully and keep it, along with the date you received it.
  • Review the explanation of benefits statements from your health insurer and ask your insurer or provider about any service you do not recognize.
  • Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion, and check your credit reports for free at annualcreditreport.com.
  • Be cautious of emails, texts or calls that mention your care or your medical details. Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against OU Medicine

If you received a notice from OU Medicine, or believe your medical information was viewed without authorization, you may have legal options. Healthcare providers are expected to protect patient records and to monitor who can see them, and a class action can help hold them accountable when they fail to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not yet disclosed
Date of Breach: December 30, 2025 to June 7, 2026
Date of Breach: October 6, 2026 (claimed, unconfirmed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.