- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,859
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The University of California Irvine Medical Center (UCI), the covered entity, reported that an employee impermissibly accessed the medical records of 4,859 patients between June of 2011 and March of 2015. The protected health information (PHI) involved included names, addresses, claims information, dates of birth, gender, medical record numbers, account numbers, and clinical information. UCI notified all affected individuals and the media. In addition, it revised its policies and procedures, sanctioned the workforce members involved, and re-trained all workforce members. In response to OCR’s investigation, UCI conducted a risk analysis and is in the process of completing a corresponding risk management plan.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.