CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumResolved
University of California, Los Angeles Health
bd_67cfe457053ac455 · schema v1 · pii pii-v1
Full breach record for University of California, Los Angeles Health →On July 3, 2015, a password-protected but unencrypted laptop owned by UCLA Health was stolen from an employee's locked vehicle. The device contained ePHI (names, medical record numbers, diagnoses, conditions, and treatment information) of approximately 1,242 individuals. The laptop was not recovered. UCLA Health notified affected individuals, media, and provided substitute notice; sanctioned and re-trained the employee; and implemented additional safeguards including laptop encryption. OCR obtained assurances corrective actions were implemented.
HIPAA clockDiscovered Jul 3, 2015 → Notified Sep 1, 201560d ✓ HIPAA 60-day OK9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,242 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 1, 2015
- Raw hash
- a2f2779dc6908b00ed507db2b411ca7c13db90e2d9d267bf39cda3a8e46a68ad
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- University of California, Los Angeles Healthnorm: university of california los angeles health
- Domain
- uclahealth.org
- Industry
- Healthcare Provider
Victim entity
- Name
- University of California, Los Angeles Healthnorm: university of california los angeles health
- Domain
- uclahealth.org
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Jul 3, 2015
- Materiality determined
- —
- Notification sent
- Sep 1, 2015
- Affected individuals
- 1,242
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Insider
- Threat actor
- External
- Regulator citations
- HHS OCR breach reportLocal law enforcement report
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- HIPAA 60-day OK · 60dHHS notified · 60d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Jul 3, 2015→ Notified: Sep 1, 201560d 60 days HIPAA 60-day OK HIPAA Discovered: Jul 3, 2015→ Notified: Sep 1, 201560d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.