Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
UC San Diego Health
bd_7fd4f4ee6122cbae · schema v1 · pii pii-v1
Full breach record for UC San Diego Health →UC San Diego Health experienced a phishing attack on January 9, 2024, resulting in unauthorized access to two employee email accounts between January 9 and January 22, 2024. The breach exposed patient information including names, Social Security numbers, medical record numbers, and clinical data. The organization secured the accounts, enhanced security controls, and offered identity theft protection services to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0e4169907efdd559HHS OCRfiled 2024-03-08Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-582207
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2024
- Raw hash
- 12aff872d454547d5a469f9cb6e7be3df729514df50cc37a3e787ef808c91b21
Reporting entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Victim entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Incident
- Discovered
- Jan 9, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.