AccidentalMisconfigurationData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICHEALTH_BASICLOCATIONMETADATALowResolved
UC San Diego Health
bd_970e0a377f0eea2f · schema v1 · pii pii-v1
Full breach record for UC San Diego Health →UC San Diego Health disclosed that its vendor, Solv Health, used unauthorized analytics tools on scheduling websites for Urgent Care and Express Care clinics between September 13 and December 22, 2022. The tools captured names, dates of birth, email addresses, IP addresses, cookies, reason for visit, and insurance type. UC San Diego Health discovered the issue in late December 2022, directed removal of the tools, transitioned to a new scheduling provider, and notified HHS and state regulators.
California clockDiscovered Dec 31, 2022 → Notified Mar 20, 202379d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1b0eda1e73546601HHS OCRfiled 2023-03-16Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564440
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2023
- Raw hash
- ef9be15634915441d4b25a4fc3ef2516414c60ec2d8ad0fe04a5ccae13ac51eb
Reporting entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Victim entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Incident
- Discovered
- Dec 31, 2022
- Materiality determined
- —
- Notification sent
- Mar 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICLOCATIONMETADATA
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- Partner
- Regulator citations
- Notified the U.S. Department of Health and Human Services and applicable California State regulatory agencies of this incident
- Third party
- via Solv Health
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- CA 60-day late · 79d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 31, 2022→ Notified: Mar 20, 202379d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.