UC San Diego Health
ent_4d07eb15b9d1d1a31cb372a8
Disclosures
8
HHS OCR · State AG · 2 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
495,949
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UC San Diego Health
- Normalized
- uc san diego health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- health.ucsd.edu
Disclosure history (8)newest first
- CALIFORNIAHHS OCRas victim2024-03-08
UC San Diego Health Hillcrest-Hillcrest Medical Center reported that several employees were targeted by an email phishing scheme, compromising PHI of 1,642 individuals. Affected data included names, addresses, email addresses, DOBs, medical record numbers, health insurance information, treatment cost information, and clinical information. The entity notified HHS, affected individuals, and the media, provided credit monitoring, and implemented additional safeguards.
- 🐻California State AGas victim2024-03-08
UC San Diego Health experienced a phishing attack on January 9, 2024, resulting in unauthorized access to two employee email accounts between January 9 and January 22, 2024. The breach exposed patient information including names, Social Security numbers, medical record numbers, and clinical data. The organization secured the accounts, enhanced security controls, and offered identity theft protection services to affected individuals.
- FEDERALHHS OCRas victim2023-03-16
The covered entity (CE), UC San Diego Health, reported that its business associate (BA) impermissibly used analytics tools on its websites that captured and transmitted the protected health information (PHI) of 22,971 individuals to its third-party service providers without a valid business associate agreement. The PHI involved included names, dates of birth, addresses, email addresses, IP addresses, and health insurance information. In its mitigation efforts, the CE terminated its business relationship with the BA, implemented new policies and procedures, and retrained workforce members to better protect PHI.
- 🐻California State AGas victim2023-03-16
UC San Diego Health disclosed that its vendor, Solv Health, used unauthorized analytics tools on scheduling websites for Urgent Care and Express Care clinics between September 13 and December 22, 2022. The tools captured names, dates of birth, email addresses, IP addresses, cookies, reason for visit, and insurance type. UC San Diego Health discovered the issue in late December 2022, directed removal of the tools, transitioned to a new scheduling provider, and notified HHS and state regulators.
- 🐻California State AGas victim2021-09-09
UC San Diego Health disclosed a security incident involving unauthorized access to employee email accounts between December 2, 2020, and April 8, 2021. The breach exposed patient personal information, including names, SSNs, medical records, and financial data. UC San Diego Health reported the incident to the FBI, engaged external cybersecurity experts, terminated unauthorized access, and offered one year of credit monitoring and identity protection services to affected individuals.
- CALIFORNIAHHS OCRas victim2021-06-08
UC San Diego Health reported to HHS on 2021-06-08 a Hacking/IT Incident affecting 495,949 individuals. Breached information located on Email. An employee was subjected to an email phishing scheme compromising PHI including names, DOB, addresses, SSN, driver's license, claims, lab results, medications, and diagnoses. The entity implemented additional safeguards and retrained staff on email security.
- 🐻California State AGas victim2019-06-14
UC San Diego Health reported a data breach involving its business associate, Nuance Communications. Between November 20 and December 9, 2017, an unauthorized third party accessed a medical transcription platform containing patient PHI, including names, DOBs, and clinical info. Nuance took the platform offline, notified law enforcement, and recovered all data. UC San Diego Health provided 24 months of identity protection to affected patients. The incident is resolved.
- 🐻California State AGas victim2016-09-22
UC San Diego School of Medicine discovered on September 7, 2016, that an electronic file containing personal information of Graduate Medical Education (GME) trainees was accessible on the internet. The file contained names, social security numbers, and internal index numbers. The breach occurred on August 3, 2016. UCSD removed the file immediately and is offering identity theft protection services to affected individuals.