University of California Irvine Medical Center
ent_9b667067bca2aa9a84804b09
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
4,859
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of California Irvine Medical Center
- Normalized
- university of california irvine medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ucihealth.org
Disclosure history (3)newest first
- California State AGas victim2015-06-17
UC Irvine Medical Center discovered on March 13, 2015, that an employee accessed patient records without a job-related purpose between June 2011 and March 2015. The accessed data included names, dates of birth, medical record numbers, diagnoses, and employment status. Forensic investigation found no evidence of data removal. The employee's access was revoked, and law enforcement was notified. Credit monitoring was offered to affected patients.
- CALIFORNIAHHS OCRas victim2015-06-17
University of California Irvine Medical Center (UCI) reported to HHS OCR on 2015-06-17 an unauthorized access/disclosure affecting 4,859 individuals. An employee impermissibly accessed patient medical records between June 2011 and March 2015. PHI exposed included names, addresses, claims information, dates of birth, gender, medical record numbers, account numbers, and clinical information, located in electronic medical records. UCI notified affected individuals and media, sanctioned staff, revised policies, and conducted a risk analysis per OCR investigation.
- California State AGas victim2014-05-14
University of California Irvine Student Health Center experienced a malware incident involving keystroke loggers on three computers between Feb 14 and Mar 27, 2014. The malware captured and transmitted data including names, unencrypted medical information (diagnoses, insurance numbers), student IDs, addresses, phone numbers, and payment details (bank name, check numbers). The incident was discovered on Mar 26, 2014. Affected individuals were offered one year of credit and internet monitoring.