Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALSMediumContained
UC San Diego Health
bd_265273fee350cb69 · schema v1 · pii pii-v1
Full breach record for UC San Diego Health →UC San Diego Health disclosed a security incident involving unauthorized access to employee email accounts between December 2, 2020, and April 8, 2021. The breach exposed patient personal information, including names, SSNs, medical records, and financial data. UC San Diego Health reported the incident to the FBI, engaged external cybersecurity experts, terminated unauthorized access, and offered one year of credit monitoring and identity protection services to affected individuals.
California clockDiscovered Jul 27, 2021 → Notified Sep 9, 202144d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545117
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2021
- Raw hash
- 3f96bbd0e639aab2de025a212f84053140846fb343e589e1c67246b905d0a40a
Reporting entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Victim entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Incident
- Discovered
- Jul 27, 2021
- Materiality determined
- —
- Notification sent
- Sep 9, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- reported the event to the FBI
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 27, 2021→ Notified: Sep 9, 202144d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.