UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION
ent_019e10e18f0b4e7dc2db4e4c0687d1e7
Disclosures
8
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
8,294
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UNIVERSITY OF CALIFORNIA, BERKELEY FOUNDATION
- Normalized
- university of california berkeley— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DH37RGR8W24T50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🐻California State AGas victim2023-04-26
California state AG breach notification sample for University of California, San Francisco, dated February 9, 2023. The filing is a template/sample and does not contain specific details regarding the nature of the breach, data types affected, or number of individuals impacted.
- CALIFORNIAHHS OCRas victim2023-04-26
University of California, San Francisco reported to HHS OCR on 2023-04-26 a Hacking/IT Incident (email phishing attack) affecting 676 individuals. An employee was the subject of a phishing attack exposing PHI including names, dates of birth, diagnoses/conditions, and other treatment information stored in Email. The CE notified HHS, affected individuals, and the media, and implemented additional safeguards and workforce retraining.
- 🐻California State AGas victim2020-11-13
On June 1, 2020, University of California San Francisco (UCSF) detected a ransomware attack on a limited part of its School of Medicine IT environment. The attacker obtained certain files and encrypted others. UCSF contained the incident, paid the ransom to decrypt data, and notified law enforcement. Affected data may include names, SSNs, health information, and financial data. UCSF offered 12 months of credit monitoring.
- 🐻California State AGas victim2015-04-30
University of California, Berkeley notified affected individuals on April 30, 2015, regarding unauthorized access to a web server in the Division of Equity & Inclusion. The breach, discovered March 14, 2015, exposed Social Security numbers and bank account numbers of students. The server was removed from the network, and forensic investigators were retained. Affected individuals received one year of credit monitoring and identity restoration services.
- 🐻California State AGas victim2015-04-10
University of California, Riverside reported the theft of a computer from its Graduate Division offices on March 13, 2015. The stolen device contained Social Security numbers paired with first and last names of graduate student applicants. The university notified affected individuals and offered complimentary identity protection services. No evidence of unauthorized use was found at the time of notification.
- 🐻California State AGas victim2014-12-12
University of California, Berkeley reported unauthorized access to servers in its Real Estate Division in mid-to-late September 2014. The breach potentially exposed names, Social Security numbers, credit card numbers, and driver's license numbers. The university shut down the servers, engaged a security firm, and offered one year of credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas victim2013-11-22
On September 25, 2013, a personal laptop and paper documents were stolen from a physician's locked car, affecting 8,294 individuals. The unencrypted laptop contained ePHI including names, addresses, SSNs, dates of birth, diagnoses, lab results, and medications. UCSF notified HHS, affected individuals, and media. In response, UCSF updated its ePHI safeguarding policies to require encryption of personally owned devices and direct possession of offsite ePHI. OCR obtained written assurances of corrective actions. Breached information located on Laptop and Paper/Films.
- CALIFORNIAHHS OCRas victim2013-10-03
On September 9, 2013, an unencrypted personal laptop and paper documents containing PHI were stolen from a UCSF workforce member's locked car. The laptop held unencrypted ePHI for 3,541 individuals; paper records covered 31 patients (3,553 total). PHI exposed included names, addresses, dates of birth, medical record numbers, Social Security numbers, diagnoses, conditions, dates of service, lab results, and medications. UCSF notified HHS, affected individuals, and media. Post-breach, workforce was retrained on encryption and PHI-handling. OCR obtained assurances of corrective action.