University of California, San Francisco
bd_fbd674aab328bdd3 · schema v1 · pii pii-v1
Full breach record for University of California, San Francisco →6 incidents on fileOn September 25, 2013, a personal laptop and paper documents were stolen from a physician's locked car, affecting 8,294 individuals. The unencrypted laptop contained ePHI including names, addresses, SSNs, dates of birth, diagnoses, lab results, and medications. UCSF notified HHS, affected individuals, and media. In response, UCSF updated its ePHI safeguarding policies to require encryption of personally owned devices and direct possession of offsite ePHI. OCR obtained written assurances of corrective actions. Breached information located on Laptop and Paper/Films.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 25, 2013
Begins
Sep 25, 2013
Discovered
Nov 22, 2013
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_da2afc3bbb8930de2013-11-21 · +1dVerified
- HHS OCRbd_18801ef8114147b02013-10-03 · +50dCandidate
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Oct 3 (CA), last Nov 22 (CA) — a 50-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.