University of California, San Francisco
bd_da2afc3bbb8930de · schema v1 · pii pii-v1
Full breach record for University of California, San Francisco →6 incidents on fileUniversity of California San Francisco (UCSF) reported the theft of an unencrypted personal laptop from a physician's vehicle on September 25, 2013. The laptop contained protected health information (PHI), names, and potentially social security numbers, dates of birth, and medical record numbers of patients. UCSF determined the scope of the breach on November 13, 2013, and notified affected individuals on November 21, 2013. The incident involved physical theft of a device containing sensitive health data.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 25, 2013
Begins
Sep 25, 2013
Discovered
Nov 21, 2013
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_fbd674aab328bdd32013-11-22 · +1dVerified
- HHS OCRbd_18801ef8114147b02013-10-03 · +49dCandidate
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Oct 3 (CA), last Nov 22 (CA) — a 50-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.