University of California, Los Angeles Health
Disclosed Jul 17, 201511 years ago4,500,000 affectedConfirmed
The University of California, Los Angeles Health, the covered entity (CE), reported to OCR that on July 3, 2015, a password-protected, unencrypted laptop computer owned by the CE was stolen from an employee’s locked vehicle. The stolen computer contained electronic protected health information (ePHI), including the names, medical record numbers, diagnoses, conditions, and other treatment information of approximately 1,242 individuals. The CE immediately reported the incident to local law enforcement, but; the laptop was not recovered. The CE provided timely breach notification to individuals and the media and provided substitute notice. Following the breach and subsequent investigation, the CE sanctioned and re-trained the employee whose laptop was stolen for failing to comply with its HIPAA policies and procedures and implemented additional technical and administrative safeguards to ensure encryption of its laptops. OCR obtained assurances that the CE implemented the corrective actions above.
What is known
| People affected | 4,500,000 (as reported to HHS) |
|---|---|
| Disclosed | Jul 17, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): University of California, Los Angeles Health (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 17, 2015 | 4,500,000 |
| HHS archivetotal | Sep 1, 2015 | 1,242 |
History of this record
- 2026-09-25 · records: 1242 to 4500000 · backfill source
- 2026-09-25 · disclosed: 2015-09-01 to 2015-07-17 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about University of California, Los Angeles Health