Vanderbilt Health notifies 3,298 patients of email data breach

Advertisement

Nashville, Tenn.-based Vanderbilt Health is notifying 3,298 patients that their medical information may have been exposed after an employee clicked a malicious link in a phishing email, according to a filing with the HHS Office for Civil Rights.

Vanderbilt discovered March 27, 2026, that an unauthorized individual had gained access to an employee’s email account through the malicious link, according to a notice from the health system. An investigation found the individual accessed certain documents in the account on March 23 and may have viewed attachments containing patient names, medical record numbers, admission, discharge or visit dates, diagnosis or procedure information, and provider or facility names.

Vanderbilt said no Social Security numbers or financial information were involved, and the incident did not affect its electronic medical record system.

Vanderbilt is notifying affected patients by mail and offering complimentary credit monitoring. The health system said it is also enhancing its email and digital security measures and expanding cybersecurity training for employees to prevent similar incidents.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement