- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 14,900
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The University of California, Davis Health, the covered entity (CE), reported that on May 15, 2017, an employee received a phishing email and provided her email login credentials, believing it was a legitimate request. On May 17, 2017, an unauthorized user in a foreign location used the employee's credentials to log into the email account and send emails to another employee, requesting funds be wired to an international location. Staff suspected a scam and promptly notified the health system's data security team, which took action to secure the account and prevent further threats. The email account contained the electronic protected health information (ePHI) of approximately 14,900 individuals and the type of ePHI involved in the incident included clinical and demographic information. The CE indicated that although there was no indication that the breach resulted in the acquisition of or access to PHI, it provided breach notification to all potentially affected individuals, HHS, and the media, and posted substituted notice. Following the breach, the CE retrained workforce members on cyber security, initiated the implementation of multi-factor authentication for external email access, and implemented technical and administrative safeguards designed to help detect and contain any future phishing attempts. OCR obtained documented assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.