University of Pittsburgh Medical Center Falls Victim to Vendor Data Breach

A health information network named “Health Gorilla” improperly accessed medical records available through the national network used to exchange medical information.

By HFT Staff


On January 13, 2026, Epic Systems (University of Pittsburgh Medical Center’s electronic medical records vendor) notified UPMC that a health information network named “Health Gorilla”, and certain participants of this network, improperly accessed medical records available through the national network used to exchange medical information.  

The purpose of the national network is to allow health providers to exchange information for the treatment of their patients.  UPMC is required to participate in this national network and is required to comply with applicable federal laws as a condition of participation. Certain participants of this network electronically requested information under the pretext of providing treatment to shared UPMC patients and allege they had permission to do so. 

In addition to this notice, UPMC provided written notice to individuals who may be affected by this incident. The information involved included a list of UPMC encounters. This may include affected individuals’ demographic information, such as name and date of birth, and information such as clinical notes, reason for visit, diagnoses, medical history and any related orders or testing. No Social Security Numbers were involved in this incident. 



March 25, 2026


Topic Area: Information Technology , Security


Recent Posts

Redefining What Mental Health Facilities Look Like

A new Mental Health and Addictions Center uses design and architecture to challenge the stigma and create a more open model of care.


Managing High-Volume Laundry Operations 

Tips and tricks one director has learned in three decades of managing a large, high-volume laundry operation.


University of Pittsburgh Medical Center Falls Victim to Vendor Data Breach

A health information network named “Health Gorilla” improperly accessed medical records available through the national network used to exchange medical information.


Optimizing the Engineering Design of Ambulatory Care Facilities

Designing cost-effective engineering systems is not about minimizing investment but about investing strategically.


Construction Completed on Washington Health Urgent Care Facility in California

The design team maximized the existing footprint to accommodate five exam rooms, a dedicated procedure room and an X-ray room.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.