UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION
bd_18801ef8114147b0 · schema v1 · pii pii-v1
Full breach record for UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION →On September 9, 2013, an unencrypted personal laptop and paper documents containing PHI were stolen from a UCSF workforce member's locked car. The laptop held unencrypted ePHI for 3,541 individuals; paper records covered 31 patients (3,553 total). PHI exposed included names, addresses, dates of birth, medical record numbers, Social Security numbers, diagnoses, conditions, dates of service, lab results, and medications. UCSF notified HHS, affected individuals, and media. Post-breach, workforce was retrained on encryption and PHI-handling. OCR obtained assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 3, 2013
- Raw hash
- 1143d15a4b8b48a14dce19b2effd720fe0136bf21f171a9f4543e5cca30cab02
Source filing
Reporting entity
- Name
- UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATIONnorm: university of california berkeley
- Domain
- ucsf.edu
- Industry
- Health Care Services
Victim entity
- Name
- UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATIONnorm: university of california berkeley
- Domain
- ucsf.edu
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Sep 9, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,553
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notified; OCR obtained assurances that corrective actions were implemented.
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 9, 2013→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.