UC Davis Medical Center
ent_97d19868a70383bbfff2f8ca
Disclosures
5
State AG · HHS OCR · 1 jurisdiction
Incidents
2
filings grouped by incident
Max affected reported
2,269
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UC Davis Medical Center
- Normalized
- uc davis medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2023-07-25
On May 24, 2023, UC Davis Health discovered that an unauthorized external individual accessed an employee's work email account. The breach potentially exposed patient health information, including names and follow-up care details. UC Davis Health froze the compromised credentials and offered 12 months of credit monitoring to affected individuals.
- 🐻California State AGas victim2014-10-13
UC Davis Health System detected unauthorized access to a provider's email account on September 26, 2014. The breach, occurring on September 25, 2014, resulted in potential impermissible access to patient health information contained in emails. No financial, billing, or social security numbers were exposed. Notifications were sent to affected patients on October 3, 2014.
- CALIFORNIAHHS OCRas victim2014-10-08
UC Davis Medical Center reported to HHS on 2014-10-08 a Hacking/IT Incident affecting 1326 individuals. Breached information located on Email. A provider's account was compromised via credential-stealing malware, exposing clinical and demographic data.
- CALIFORNIAHHS OCRas victim2014-02-14
UC Davis Medical Center reported to HHS on 2014-02-14 a Hacking/IT Incident affecting 2269 individuals. Breached information located on Email. A fraudulent phishing email instructed employees to input authentication credentials on a fake site, impacting three accounts containing ePHI of 2,269 individuals.
- 🐻California State AGas victim2014-02-03
UC Davis Health System notified patients that a medical provider's email account was compromised via a phishing scam on December 13, 2013. Affected data included names, medical record numbers, and clinic visit dates. No financial information or SSNs were involved. The organization deleted the phishing email, blocked the website, and warned staff.