University of California, Los Angeles Health
bd_67cfe457053ac455 · schema v1 · pii pii-v1
Full breach record for University of California, Los Angeles Health →7 incidents on fileOn July 3, 2015, a password-protected but unencrypted laptop owned by UCLA Health was stolen from an employee's locked vehicle. The device contained ePHI (names, medical record numbers, diagnoses, conditions, and treatment information) of approximately 1,242 individuals. The laptop was not recovered. UCLA Health notified affected individuals, media, and provided substitute notice; sanctioned and re-trained the employee; and implemented additional safeguards including laptop encryption. OCR obtained assurances corrective actions were implemented.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 3, 2015
Begins
Jul 3, 2015
Discovered
Sep 1, 2015
Filed
vs. sector median
2 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.