← University of Nebraska Medical Center

2026 UNMC — REDCap software vulnerability exploited 2023–2026 (26,937 individuals)

2026 26.9K records affected Share on X

Data compromised

Names, DOB, addresses, medical information, some SSNs (varied by individual)

Technical writeup

The University of Nebraska Medical Center (UNMC) disclosed in May 2026 that a vulnerability in the third-party REDCap research software was exploited by a threat actor, exposing protected health information for 26,937 individuals. UNMC learned of the flaw in February 2026, took REDCap offline, and—with third-party forensics—determined access was possible from September 20, 2023 through February 3, 2026. REDCap supports UNMC research studies and public health activities. Exposed data categories varied by individual and could include names, dates of birth, addresses, medical information, and some Social Security numbers per HIPAA Journal’s May 2026 roundup.

Root cause

Exploitation of REDCap application vulnerability (third-party research software)

References