Skip to content

UC Davis Medical Center, Privacy Manager Breach

Disclosed Feb 14, 201412 years ago2,269 affectedConfirmed

Official notice

The University of California, Davis Medical Center (UCDMC), the covered entity (CE), reported that on September 26, 2014, its information technology team detected abnormal activity in the email account of a UCDMC medical provider. UCDMC determined that the provider’s email account was compromised by an unknown source (i.e., a “hacker”) resulting in potential impermissible access to the account. UCDMC determined that the provider likely used a compromised computer with credential-stealing malware when logging on remotely to the UCDMC webmail site. In response, UCDMC immediately changed the email user’s credentials and took steps to secure its email system. UCDMC reviewed the entire content of the provider’s email account to ascertain whether any electronic protected health information was contained therein. UCDMC determined that clinical and demographic information pertaining to 1,326 patients resided in the email account. UCDMC audited the entire email system to ensure that no other email accounts were similarly impacted. UCDMC provided notification to the affected individuals and issued a press release to the media. OCR obtained assurances that UCDMC implemented the corrective act

What is known

People affected2,269 (as reported to HHS)
DisclosedFeb 14, 2014
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalFeb 14, 20142,269
HHS archivetotalOct 8, 20141,326
History of this record
  • 2026-09-25 · records: 1326 to 2269 · backfill source
  • 2026-09-25 · disclosed: 2014-10-08 to 2014-02-14 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about UC Davis Medical Center, Privacy Manager Breach

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.