UCLA Health
bd_0c9ea43643627ff0 · schema v1 · pii pii-v1
UCLA Health disclosed a cyberattack where an unauthorized third party accessed parts of the network containing personal and medical information. The attacker may have had access as early as September 2014, but UCLA Health determined access occurred on May 5, 2015. Affected data includes names, addresses, SSNs, medical record numbers, and medical information. The investigation is ongoing with FBI assistance.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2014
Begins
May 5, 2015
Discovered
Jul 17, 2015
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_35a747e70f5a1fbb2015-07-17Verified
- HHS OCRbd_eef61580e59756ac2015-07-17Verified
- Massachusetts State AGbd_a78328bfdfbbe63f2015-07-20 · +3dVerified
- Hawaii State AGbd_5ca3b58d29fa8c482015-07-22 · +5dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jul 17 (NH), last Jul 22 (HI) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.