Universal Care
Disclosed Feb 10, 20179 years ago14,005 affectedConfirmed
On February 10, 2017, Universal Care, Inc., DBA Brand New Day, the covered entity, reported to OCR that an unauthorized individual had downloaded electronic protected health information (ePHI) related to the CE's members. The ePHI was on a computer system maintained by a third-party vendor, a business associate (BA). The breach affected the clinical and demographic information of approximately 14,005 individuals. Following the breach incident, the CE obtained assurances from the BA that it had implemented additional administrative and technical safeguards to prevent unauthorized access to ePHI in the future. The CE provided breach notification to HHS, affected individuals, and the media. It also offered 12 months of free credit monitoring services to the affected individuals. OCR obtained assurances that the CE implemented the corrective action measures described.
What is known
| People affected | 14,005 (as reported to HHS) |
|---|---|
| Disclosed | Feb 10, 2017 |
| Happened | Dec 22, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Universal Careoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Universal Care (Health Plan, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 10, 2017 | 14,005 |
| California AGresidents of CA | Mar 3, 2017 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 14005 · backfill source
- 2026-09-25 · disclosed: 2017-03-03 to 2017-02-10 · backfill source
- 2026-09-25 · summary: empty to On February 10, 2017, Universal Care, Inc., DBA Brand New Day, the covered entity, reported to OCR that an unauthorized individual had downloaded electronic protected health information (ePHI) related to the CE's members. The ePHI was on a · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.