CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighResolved
University of San Francisco (UCSF)
bd_1bae61a2fce44bfa · schema v1 · pii pii-v1
Full breach record for University of San Francisco (UCSF) →University of California San Francisco Family Medicine Center reported to HHS on 2014-03-12 a Theft affecting 9,861 individuals. On or about January 11, 2014, unencrypted desktop computers and portable computer drives were stolen. PHI exposed included names, dates of birth, mailing addresses, medical record numbers, Social Security numbers, and health insurance ID numbers. The CE improved physical safeguards, rotated credentials, and encrypted remaining and replacement computers. OCR obtained corrective-action assurances.
HIPAA clock✓ HHS notified9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed9,861 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 12, 2014
- Raw hash
- 6589e066775be25289f75d92d26e17eb4d91e13f460dc35a7414a64718aa4904
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- University of San Francisco (UCSF)norm: university of san francisco ucsf
- Domain
- ucsf.edu
- Industry
- Health Care Services
Victim entity
- Name
- University of San Francisco (UCSF)norm: university of san francisco ucsf
- Domain
- ucsf.edu
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Jan 11, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 9,861
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notification — OCR obtained assurances that corrective actions were implemented
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jan 11, 2014→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.