Skip to content

University of California, Los Angeles Health

Disclosed Jul 17, 201511 years ago4,500,000 affectedConfirmed

Official notice

The University of California, Los Angeles Health, the covered entity (CE), reported to OCR that on July 3, 2015, a password-protected, unencrypted laptop computer owned by the CE was stolen from an employee’s locked vehicle. The stolen computer contained electronic protected health information (ePHI), including the names, medical record numbers, diagnoses, conditions, and other treatment information of approximately 1,242 individuals. The CE immediately reported the incident to local law enforcement, but; the laptop was not recovered. The CE provided timely breach notification to individuals and the media and provided substitute notice. Following the breach and subsequent investigation, the CE sanctioned and re-trained the employee whose laptop was stolen for failing to comply with its HIPAA policies and procedures and implemented additional technical and administrative safeguards to ensure encryption of its laptops. OCR obtained assurances that the CE implemented the corrective actions above.

What is known

People affected4,500,000 (as reported to HHS)
DisclosedJul 17, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 17, 20154,500,000
HHS archivetotalSep 1, 20151,242
History of this record
  • 2026-09-25 · records: 1242 to 4500000 · backfill source
  • 2026-09-25 · disclosed: 2015-09-01 to 2015-07-17 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about University of California, Los Angeles Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.