UCLA Health System announces data breach affecting 4.5 million patients and medical providers

Robinson+Cole Data Privacy + Security Insider
Contact

Adding to the long list of cyber hacking victims, the UCLA Health System announced on Friday (July 17, 2015) that it confirmed on May 5, 2015 that a cyber-attacker had accessed parts of UCLA Health’s network back to September of 2014. The information accessed included 4.5 million patient names, addresses, dates of birth, Social Security numbers, medical record numbers, Medicare and/or health plan ID number and medical information, as well as information on UCLA providers who sought privileges at any UCLA Health hospital. The UCLA system includes Ronald Reagan UCLA Medical Center; UCLA Medical Center, Santa Monica; Mattel Children’s Hospital UCLA; and Resnick Neuropsychiatric Hospital at UCLA.

Not only are the HIPAA breach notification regulations applicable here, UCLA has not provided any public information regarding the sensitive psychiatric information that may have been accessed from the Resnick Neuropsychiatric Hospital, which could include substance abuse treatment information protected by 42 C.F.R Part 2 and regulated by the Substance Abuse and Mental Health Services Administration, as well as state laws that apply to highly sensitive health information regulated by state authorities.

UCLA is working with the FBI and a forensic firm in an ongoing investigation and is offering free identity theft recovery and restoration services and credit monitoring for affected individuals.

This is not the first time UCLA has had HIPAA issues. In July of 2011, it settled alleged HIPAA violations with the Office for Civil Rights for $865,500 and entered into a Resolution Agreement and Corrective Action Plan following an OCR investigation. The allegations were that employees repeatedly and without permission examined the health information of patients (rumored to be famous individuals) between 2005-2008.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide