HackingStolen CredentialsTargetedIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTLowContained
University of California Irvine Medical Center
bd_2d77e3bb8f7b1345 · schema v1 · pii pii-v1
Full breach record for University of California Irvine Medical Center →University of California Irvine notified affected individuals that a keystroke logger infected three computers in the Student Health Center between Feb 14 and Mar 27, 2014. The malware captured unencrypted medical info, names, IDs, and payment details. UC Irvine contained the incident, reported to law enforcement, and offered one year of credit/internet monitoring.
California clockDiscovered Mar 26, 2014 → Notified Apr 21, 201426d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45106
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2014
- Raw hash
- b4618a21907ebf4ed9bec5c0f7d6ecd0f48b0feaa6b6634f96e58db1bd08a09a
Reporting entity
- Name
- University of California Irvine Medical Centernorm: university of california irvine medical center
- Domain
- ucihealth.org
Victim entity
- Name
- University of California Irvine Medical Centernorm: university of california irvine medical center
- Domain
- ucihealth.org
Incident
- Discovered
- Mar 26, 2014
- Materiality determined
- —
- Notification sent
- Apr 21, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1071 Application Layer Protocol
- Threat actor
- External
- Regulator citations
- Notified by the California Information Security Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 26d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 26, 2014→ Notified: Apr 21, 201426d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.