- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,326
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The University of California, Davis Medical Center (UCDMC), the covered entity (CE), reported that on September 26, 2014, its information technology team detected abnormal activity in the email account of a UCDMC medical provider. UCDMC determined that the provider’s email account was compromised by an unknown source (i.e., a “hacker”) resulting in potential impermissible access to the account. UCDMC determined that the provider likely used a compromised computer with credential-stealing malware when logging on remotely to the UCDMC webmail site. In response, UCDMC immediately changed the email user’s credentials and took steps to secure its email system. UCDMC reviewed the entire content of the provider’s email account to ascertain whether any electronic protected health information was contained therein. UCDMC determined that clinical and demographic information pertaining to 1,326 patients resided in the email account. UCDMC audited the entire email system to ensure that no other email accounts were similarly impacted. UCDMC provided notification to the affected individuals and issued a press release to the media. OCR obtained assurances that UCDMC implemented the corrective action described above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.