Back to the register

University of California, Los Angeles Health

ArchivedSubmitted 09/01/2015
State
CA
Covered entity type
Healthcare Provider
Individuals affected
1,242
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The University of California, Los Angeles Health, the covered entity (CE), reported to OCR that on July 3, 2015, a password-protected, unencrypted laptop computer owned by the CE was stolen from an employee’s locked vehicle. The stolen computer contained electronic protected health information (ePHI), including the names, medical record numbers, diagnoses, conditions, and other treatment information of approximately 1,242 individuals. The CE immediately reported the incident to local law enforcement, but; the laptop was not recovered. The CE provided timely breach notification to individuals and the media and provided substitute notice. Following the breach and subsequent investigation, the CE sanctioned and re-trained the employee whose laptop was stolen for failing to comply with its HIPAA policies and procedures and implemented additional technical and administrative safeguards to ensure encryption of its laptops. OCR obtained assurances that the CE implemented the corrective actions above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.