Skip to content

University of California, San Francisco

Disclosed Apr 26, 20233 years ago676 affectedConfirmed

Official notice

The covered entity (CE), University of California, San Francisco, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 676 individuals. The PHI involved included names, dates of birth, diagnoses/conditions, and other treatment information. The CE notified HHS, the affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards and retrained its workforce members to better protect its PHI.

What is known

People affected676 (as reported to HHS)
DisclosedApr 26, 2023
HappenedFeb 9, 2023
AttackHacking
Data exposedNames, Health
SectorEducation · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CAApr 26, 2023
HHS archivetotalApr 26, 2023676

Other breaches at University of California, San Francisco

BreachAffected
Disclosed Nov 13, 2020Nov 13, 20205 years agoUnknown
Disclosed Oct 3, 2013Oct 3, 201312 years agoLost or stolen device8,294
Disclosed Dec 15, 2009Dec 15, 200916 years agoLost or stolen device7,300
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 676 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), University of California, San Francisco, reported that an employee was the subject of an email phishing attack that affected the protected health information (PHI) of 676 individuals. The PHI involved included names · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about University of California, San Francisco

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.