HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedPHIHEALTH_BASICIDENTITY_BASICLowResolved
UC San Diego Health
bd_ddd25e1d4a62bc53 · schema v1 · pii pii-v1
Full breach record for UC San Diego Health →UC San Diego Health reported a data breach involving its business associate, Nuance Communications. Between November 20 and December 9, 2017, an unauthorized third party accessed a medical transcription platform containing patient PHI, including names, DOBs, and clinical info. Nuance took the platform offline, notified law enforcement, and recovered all data. UC San Diego Health provided 24 months of identity protection to affected patients. The incident is resolved.
California clockDiscovered Dec 22, 2017 → Notified Jun 28, 2018188d ✗ CA 60-day late18 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-148112
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 14, 2019
- Raw hash
- ef71a65950fb36c575110fc931ad449c37ece765479a6b470e2e6bbce8cff93c
Reporting entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Victim entity
- Name
- UC San Diego Healthnorm: uc san diego health
- Domain
- health.ucsd.edu
Incident
- Discovered
- Dec 22, 2017
- Materiality determined
- —
- Notification sent
- Jun 28, 2018
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via Nuance Communications
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 months(539 days from discovery to filing)
- Compliance flags
- CA 60-day late · 188d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 22, 2017→ Notified: Jun 28, 2018188d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.