UC Davis Health
Disclosed Jul 25, 20233 years ago3,201 affectedConfirmed
The covered entity (CE), UC Davis Health, reported that an employee was the subject of an email phishing attack that compromised the protected health information (PHI) of 3,201 individuals. The PHI involved included names, dates of birth, Social Security numbers, diagnoses, and medications. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards.
What is known
| People affected | 3,201 (as reported to HHS) |
|---|---|
| Disclosed | Jul 25, 2023 |
| Happened | May 24, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: UC Davis Healthoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): UC Davis Health (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jul 25, 2023 | |
| HHS archivetotal | Jul 28, 2023 | 3,201 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 3201 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), UC Davis Health, reported that an employee was the subject of an email phishing attack that compromised the protected health information (PHI) of 3,201 individuals. The PHI involved included names, dates of birth, S · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.