UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION
bd_fbd674aab328bdd3 · schema v1 · pii pii-v1
Full breach record for UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION →On September 25, 2013, a personal laptop and paper documents were stolen from a physician's locked car, affecting 8,294 individuals. The unencrypted laptop contained ePHI including names, addresses, SSNs, dates of birth, diagnoses, lab results, and medications. UCSF notified HHS, affected individuals, and media. In response, UCSF updated its ePHI safeguarding policies to require encryption of personally owned devices and direct possession of offsite ePHI. OCR obtained written assurances of corrective actions. Breached information located on Laptop and Paper/Films.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 22, 2013
- Raw hash
- f8725b2173ed781d2ceece64eeb9cbc8ea1440795845ca4cf73bef738d474826
Source filing
Reporting entity
- Name
- UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATIONnorm: university of california berkeley
- Domain
- ucsf.edu
- Industry
- Health Care Services
Victim entity
- Name
- UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATIONnorm: university of california berkeley
- Domain
- ucsf.edu
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Sep 25, 2013
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 8,294
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notified; OCR obtained written assurances of corrective action implementation
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Sep 25, 2013→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.