University of California, San Francisco
ent_99ceba358860f6e8ceda1d7a
Disclosures
10
State AG · HHS OCR · Leak Site · 2 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
9,861
nationwide · HHS OCR CA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- University of California, San Francisco
- Normalized
- university of california san francisco— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ucsf.edu
Disclosure history (10)newest first
- California State AGas victim2023-04-26
California state AG breach notification sample for University of California, San Francisco, dated February 9, 2023. The filing is a template/sample and does not contain specific details regarding the nature of the breach, data types affected, or number of individuals impacted.
- CALIFORNIAHHS OCRas victim2023-04-26
University of California, San Francisco reported to HHS OCR on 2023-04-26 a Hacking/IT Incident (email phishing attack) affecting 676 individuals. An employee was the subject of a phishing attack exposing PHI including names, dates of birth, diagnoses/conditions, and other treatment information stored in Email. The CE notified HHS, affected individuals, and the media, and implemented additional safeguards and workforce retraining.
- California State AGas victim2020-11-13
On June 1, 2020, University of California San Francisco (UCSF) detected a ransomware attack on a limited part of its School of Medicine IT environment. The attacker obtained certain files and encrypted others. UCSF contained the incident, paid the ransom to decrypt data, and notified law enforcement. Affected data may include names, SSNs, health information, and financial data. UCSF offered 12 months of credit monitoring.
- GLOBALLeak Siteas victim2020-06-01
- CALIFORNIAHHS OCRas victim2014-03-12
University of California San Francisco Family Medicine Center reported to HHS on 2014-03-12 a Theft affecting 9,861 individuals. On or about January 11, 2014, unencrypted desktop computers and portable computer drives were stolen. PHI exposed included names, dates of birth, mailing addresses, medical record numbers, Social Security numbers, and health insurance ID numbers. The CE improved physical safeguards, rotated credentials, and encrypted remaining and replacement computers. OCR obtained corrective-action assurances.
- CALIFORNIAHHS OCRas victim2013-11-22
On September 25, 2013, a personal laptop and paper documents were stolen from a physician's locked car, affecting 8,294 individuals. The unencrypted laptop contained ePHI including names, addresses, SSNs, dates of birth, diagnoses, lab results, and medications. UCSF notified HHS, affected individuals, and media. In response, UCSF updated its ePHI safeguarding policies to require encryption of personally owned devices and direct possession of offsite ePHI. OCR obtained written assurances of corrective actions. Breached information located on Laptop and Paper/Films.
- California State AGas victim2013-11-21
University of California San Francisco (UCSF) reported the theft of an unencrypted personal laptop from a physician's vehicle on September 25, 2013. The laptop contained protected health information (PHI), names, and potentially social security numbers, dates of birth, and medical record numbers of patients. UCSF determined the scope of the breach on November 13, 2013, and notified affected individuals on November 21, 2013. The incident involved physical theft of a device containing sensitive health data.
- CALIFORNIAHHS OCRas victim2013-10-03
On September 9, 2013, an unencrypted personal laptop and paper documents containing PHI were stolen from a UCSF workforce member's locked car. The laptop held unencrypted ePHI for 3,541 individuals; paper records covered 31 patients (3,553 total). PHI exposed included names, addresses, dates of birth, medical record numbers, Social Security numbers, diagnoses, conditions, dates of service, lab results, and medications. UCSF notified HHS, affected individuals, and media. Post-breach, workforce was retrained on encryption and PHI-handling. OCR obtained assurances of corrective action.
- CALIFORNIAHHS OCRas victim2010-01-27
University of California, San Francisco reported to HHS OCR on 2010-01-27 a Theft affecting 7,300 individuals. Breached information was located on a Laptop. No business associate was involved. No further description was provided by the covered entity.
- CALIFORNIAHHS OCRas victim2009-12-15
University of California, San Francisco reported to HHS on 2009-12-15 a breach of type 'Other' affecting 610 individuals. Breached information located on Email.