University of California Davis Health
Disclosed Jul 6, 20179 years ago14,900 affectedConfirmed
The University of California, Davis Health, the covered entity (CE), reported that on May 15, 2017, an employee received a phishing email and provided her email login credentials, believing it was a legitimate request. On May 17, 2017, an unauthorized user in a foreign location used the employee's credentials to log into the email account and send emails to another employee, requesting funds be wired to an international location. Staff suspected a scam and promptly notified the health system's data security team, which took action to secure the account and prevent further threats. The email account contained the electronic protected health information (ePHI) of approximately 14,900 individuals and the type of ePHI involved in the incident included clinical and demographic information. The CE indicated that although there was no indication that the breach resulted in the acquisition of or access to PHI, it provided breach notification to all potentially affected individuals, HHS, and the media, and posted substituted notice. Following the breach, the CE retrained workforce members on cyber security, initiated the implementation of multi-factor authentication for external email acces
What is known
| People affected | 14,900 (as reported to HHS) |
|---|---|
| Disclosed | Jul 6, 2017 |
| Happened | May 17, 2017 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: University of California Davis Healthoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): University of California Davis Health (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jul 6, 2017 | |
| HHS archivetotal | Jul 6, 2017 | 14,900 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 14900 · backfill source
- 2026-09-25 · summary: empty to The University of California, Davis Health, the covered entity (CE), reported that on May 15, 2017, an employee received a phishing email and provided her email login credentials, believing it was a legitimate request. On May 17, 2017, an u · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.