DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIHealth (basic)Identity (basic)MediumResolved

University of California, Los Angeles Health

bd_67cfe457053ac455 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jul 3, 2015

Filed

Sep 1, 2015

To disclose

9 weeks

Affected

1,242

Confidence

91%
Full breach record for University of California, Los Angeles Health7 incidents on file

On July 3, 2015, a password-protected but unencrypted laptop owned by UCLA Health was stolen from an employee's locked vehicle. The device contained ePHI (names, medical record numbers, diagnoses, conditions, and treatment information) of approximately 1,242 individuals. The laptop was not recovered. UCLA Health notified affected individuals, media, and provided substitute notice; sanctioned and re-trained the employee; and implemented additional safeguards including laptop encryption. OCR obtained assurances corrective actions were implemented.

HIPAA clockDiscovered Jul 3, 2015Notified Sep 1, 201560d HHS report on time9 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 9 weeks / 60 days

Jul 3, 2015

Begins

Jul 3, 2015

Discovered

Sep 1, 2015

Filed

vs. sector median

2 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,242 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.