University of California, Berkeley
ent_8351d06bb927384504586e4b
Disclosures
8
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
8,294
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of California, Berkeley
- Normalized
- university of california berkeley— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DH37RGR8W24T50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- berkeley.edu
Disclosure history (8)newest first
- California State AGas reporting2023-04-26
California state AG breach notification sample for University of California, San Francisco, dated February 9, 2023. The filing is a template/sample and does not contain specific details regarding the nature of the breach, data types affected, or number of individuals impacted.
- CALIFORNIAHHS OCRas reporting2023-04-26
University of California, San Francisco reported to HHS OCR on 2023-04-26 a Hacking/IT Incident (email phishing attack) affecting 676 individuals. An employee was the subject of a phishing attack exposing PHI including names, dates of birth, diagnoses/conditions, and other treatment information stored in Email. The CE notified HHS, affected individuals, and the media, and implemented additional safeguards and workforce retraining.
- California State AGas victim2015-04-30
University of California, Berkeley disclosed unauthorized access to a web server maintained by the Division of Equity & Inclusion. The breach, discovered on March 14, 2015, involved access occurring between December 2014 and February 2015. Affected data may include social security numbers, bank account numbers, and family financial information of students. The university removed the server, engaged forensic investigators, and offered credit monitoring.
- California State AGas reporting2015-04-10
University of California, Riverside reported the theft of a computer from its Graduate Division offices on March 13, 2015. The stolen device contained Social Security numbers paired with first and last names of graduate student applicants. The university notified affected individuals and offered complimentary identity protection services. No evidence of unauthorized use was found at the time of notification.
- California State AGas victim2014-12-12
University of California, Berkeley reported unauthorized access to servers in its Real Estate Division in mid-to-late September 2014. The breach potentially exposed names, Social Security numbers, credit card numbers, and driver's license numbers. The university shut down the servers, engaged a security firm, and offered one year of credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas reporting2013-11-22
On September 25, 2013, a personal laptop and paper documents were stolen from a physician's locked car, affecting 8,294 individuals. The unencrypted laptop contained ePHI including names, addresses, SSNs, dates of birth, diagnoses, lab results, and medications. UCSF notified HHS, affected individuals, and media. In response, UCSF updated its ePHI safeguarding policies to require encryption of personally owned devices and direct possession of offsite ePHI. OCR obtained written assurances of corrective actions. Breached information located on Laptop and Paper/Films.
- CALIFORNIAHHS OCRas reporting2013-10-03
On September 9, 2013, an unencrypted personal laptop and paper documents containing PHI were stolen from a UCSF workforce member's locked car. The laptop held unencrypted ePHI for 3,541 individuals; paper records covered 31 patients (3,553 total). PHI exposed included names, addresses, dates of birth, medical record numbers, Social Security numbers, diagnoses, conditions, dates of service, lab results, and medications. UCSF notified HHS, affected individuals, and media. Post-breach, workforce was retrained on encryption and PHI-handling. OCR obtained assurances of corrective action.
- CALIFORNIAHHS OCRas reporting2009-12-15
University of California, San Francisco reported to HHS on 2009-12-15 a breach of type 'Other' affecting 610 individuals. Breached information located on Email.