University of California, Los Angeles Health
ent_c5ff3042d7f4f967b8e18976
Disclosures
6
HHS OCR · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
4,500,000
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- University of California, Los Angeles Health
- Normalized
- university of california los angeles health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- uclahealth.org
Disclosure history (6)newest first
- CALIFORNIAHHS OCRas victim2022-09-08
UCLA Health (CA) reported to HHS on 2022-09-08 a Loss affecting 2,190 individuals. An unencrypted USB drive containing PHI — including names, dates of birth, diagnoses, and other treatment information — was misplaced and not recovered. Breached information located on Other Portable Electronic Device. The CE notified HHS, affected individuals, and the media, and responded with additional technical safeguards, revised policies and procedures, and workforce retraining.
- 🦬Montana State AGas victim2019-04-05
UCLA Health reported a data breach to the Montana Attorney General. The breach was reported on 2019-04-05. The breach occurred from 11/26/2018 to 4/4/2019. 1 Montana residents were affected.
- CALIFORNIAHHS OCRas victim2015-09-01
On July 3, 2015, a password-protected but unencrypted laptop owned by UCLA Health was stolen from an employee's locked vehicle. The device contained ePHI (names, medical record numbers, diagnoses, conditions, and treatment information) of approximately 1,242 individuals. The laptop was not recovered. UCLA Health notified affected individuals, media, and provided substitute notice; sanctioned and re-trained the employee; and implemented additional safeguards including laptop encryption. OCR obtained assurances corrective actions were implemented.
- 🌺Hawaii State AGas victim2015-07-22
UCLA Health Services reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2015/07.22. Breach type: Hackers/Unauthorized Access. 5,446 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- 🐻California State AGas victim2015-07-17
UCLA Health reported a cyberattack in California affecting patient data including names, SSNs, DOBs, and medical records. The breach occurred as early as September 2014, discovered May 2015. FBI and forensic experts are investigating. ID Experts provided credit monitoring and identity theft recovery services.
- CALIFORNIAHHS OCRas victim2015-07-17
UCLA Health reported to HHS on 2015-07-17 a Hacking/IT Incident affecting approximately 4,500,000 individuals. A hacker accessed parts of the covered entity's computer network containing clinical and demographic information. The incident was reported to the FBI and a forensic analysis was conducted. Breach notifications were sent to HHS, affected individuals, and the media. The CE implemented technical and administrative safeguards following the breach. OCR obtained assurances of corrective action. Breached information located on Network Server.