DisclosureLens
HackingHealthcareHealthcareBusiness Associate (HIPAA)Customer Data InvolvedSupply Chain (3P Vendor)PHIHealth (basic)Identity (basic)LowResolved

UC San Diego Health

bd_ddd25e1d4a62bc53 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 22, 2017

Filed

Jun 14, 2019

To disclose

18 months

Affected

Not disclosed

Confidence

64%
Full breach record for UC San Diego Health6 incidents on file

UC San Diego Health notified patients that an unauthorized third party accessed medical information via a business associate, Nuance Communications, between Nov 20 and Dec 9, 2017. UCSD learned of the incident on Dec 22, 2017. Affected data included names, DOB, gender, MRNs, and clinical info. No SSNs or financial data were involved. Nuance took the platform offline and notified law enforcement. Identity protection services were offered.

California clockDiscovered Dec 22, 2017Notified Jun 28, 2018188d CA 60-day late18 months discovery → filing

Incident timeline

undetected · 32 days
discovery → filing · 18 months / 539 days

Nov 20, 2017

Begins

Dec 22, 2017

Discovered

Jun 14, 2019

Filed

vs. sector median

+66 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.