University of California, Los Angeles Health
ent_c5ff3042d7f4f967b8e18976
Disclosures
11
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,500,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of California, Los Angeles Health
- Normalized
- university of california los angeles health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- uclahealth.org
Disclosure history (11)newest first
- California State AGas reporting2026-08-04
UCLA Health reported a breach of protected health information (PHI) involving patient records. The incident involved unauthorized access and disclosure of patient information to an outside healthcare provider in a manner inconsistent with policies. Affected data included names, addresses, dates of birth, health insurance info, clinical info, and for some, the last four digits of SSNs. No full SSNs or financial account numbers were involved. UCLA Health initiated an investigation, deployed additional monitoring, and enhanced system controls. Complimentary identity monitoring was offered.
- CALIFORNIAHHS OCRas reporting2023-01-12
UCLA Health reported to HHS on 2023-01-12 a Unauthorized Access/Disclosure affecting 94,000 individuals. Breached information located on Network Server. Analytic tools on its website may have transmitted PHI including names, dates of birth, and other identifiers to service providers.
- CALIFORNIAHHS OCRas reporting2022-09-08
UCLA Health (CA) reported to HHS on 2022-09-08 a Loss affecting 2,190 individuals. An unencrypted USB drive containing PHI — including names, dates of birth, diagnoses, and other treatment information — was misplaced and not recovered. Breached information located on Other Portable Electronic Device. The CE notified HHS, affected individuals, and the media, and responded with additional technical safeguards, revised policies and procedures, and workforce retraining.
- Montana State AGas reporting2019-04-05
UCLA Health notified Montana residents of a data breach involving Eurofins VRL, Inc. Unauthorized access to an employee email account occurred between Nov 26 and Dec 20, 2018. Affected data included names and medical information (CPT codes). UCLA retained forensic investigators and Kroll for credit monitoring. No evidence of misuse was found.
- CALIFORNIAHHS OCRas victim2015-09-01
On July 3, 2015, a password-protected but unencrypted laptop owned by UCLA Health was stolen from an employee's locked vehicle. The device contained ePHI (names, medical record numbers, diagnoses, conditions, and treatment information) of approximately 1,242 individuals. The laptop was not recovered. UCLA Health notified affected individuals, media, and provided substitute notice; sanctioned and re-trained the employee; and implemented additional safeguards including laptop encryption. OCR obtained assurances corrective actions were implemented.
- Hawaii State AGas reporting2015-07-22
UCLA Health notified Hawaii OCP of a cyberattack where an attacker accessed the network starting as early as September 2014. On May 5, 2015, UCLA determined access occurred. 5,446 Hawaii residents were notified on July 17, 2015. Data at risk included names, SSNs, DOBs, medical info. FBI and forensic experts engaged. Identity theft services offered.
- Massachusetts State AGas reporting2015-07-20
UCLA Health Systems reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-07-20. 4,667 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas reporting2015-07-17
UCLA Health disclosed a cyberattack where an unauthorized third party accessed parts of the network containing personal and medical information. The attacker may have had access as early as September 2014, but UCLA Health determined access occurred on May 5, 2015. Affected data includes names, addresses, SSNs, medical record numbers, and medical information. The investigation is ongoing with FBI assistance.
- New Hampshire State AGas reporting2015-07-17
UCLA Health notified New Hampshire AG of a cyberattack where attackers accessed the network starting Sept 2014. Discovered May 5, 2015. 517 NH residents potentially impacted. Data at risk included names, SSNs, DOBs, medical info. FBI engaged, forensics experts retained. Identity theft services and credit monitoring offered.
- CALIFORNIAHHS OCRas victim2015-07-17
UCLA Health reported to HHS on 2015-07-17 a Hacking/IT Incident affecting approximately 4,500,000 individuals. A hacker accessed parts of the covered entity's computer network containing clinical and demographic information. The incident was reported to the FBI and a forensic analysis was conducted. Breach notifications were sent to HHS, affected individuals, and the media. The CE implemented technical and administrative safeguards following the breach. OCR obtained assurances of corrective action. Breached information located on Network Server.
- CALIFORNIAHHS OCRas reporting2011-11-04
UCLA Health System reported to HHS on 2011-11-04 a Theft affecting 2761 individuals. Breached information located on Other, Other Portable Electronic Device.