UCLA Health
bd_5ca3b58d29fa8c48 · schema v1 · pii pii-v1
UCLA Health notified Hawaii OCP of a cyberattack where an attacker accessed the network starting as early as September 2014. On May 5, 2015, UCLA determined access occurred. 5,446 Hawaii residents were notified on July 17, 2015. Data at risk included names, SSNs, DOBs, medical info. FBI and forensic experts engaged. Identity theft services offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 1, 2014
Begins
May 5, 2015
Discovered
Jul 22, 2015
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_a78328bfdfbbe63f2015-07-20 · +2dVerified
- California State AGbd_0c9ea43643627ff02015-07-17 · +5dCandidate
- New Hampshire State AGbd_35a747e70f5a1fbb2015-07-17 · +5dVerified
- HHS OCRbd_eef61580e59756ac2015-07-17 · +5dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Jul 17 (CA), last Jul 22 (HI) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.