University of California, San Francisco
bd_18801ef8114147b0 · schema v1 · pii pii-v1
Full breach record for University of California, San Francisco →6 incidents on fileOn September 9, 2013, an unencrypted personal laptop and paper documents containing PHI were stolen from a UCSF workforce member's locked car. The laptop held unencrypted ePHI for 3,541 individuals; paper records covered 31 patients (3,553 total). PHI exposed included names, addresses, dates of birth, medical record numbers, Social Security numbers, diagnoses, conditions, dates of service, lab results, and medications. UCSF notified HHS, affected individuals, and media. Post-breach, workforce was retrained on encryption and PHI-handling. OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 9, 2013
Begins
Sep 9, 2013
Discovered
Oct 3, 2013
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_da2afc3bbb8930de2013-11-21 · +49dVerified
- HHS OCRbd_fbd674aab328bdd32013-11-22 · +50dVerified
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Oct 3 (CA), last Nov 22 (CA) — a 50-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.