UC San Diego Health Suffers Data Breach

Aug. 3, 2021
UC San Diego Health reports that hackers accessed personal data including claims information, lab results, Social Security numbers, and payment card numbers

Leaders at UC San Diego Health released a notice on July 27 that they “recently experienced a security event involving unauthorized access to some employee email accounts.”

According to ZDNet, “From December 2, 2020 to April 8, 2021, hackers had access to data including names, addresses, claims information, laboratory results, medical diagnosis and conditions, Medical Record Numbers and other medical identifiers, prescription information, treatment information, medical information, Social Security numbers, government identification numbers, payment card numbers or financial account numbers and security codes, student ID numbers, and usernames and passwords.”

ZDNet also reported that “In an FAQ attached to the notice, the hospital said it discovered suspicious activity on March 12 but it took until April 8 for its security team to officially identify it as ‘a security matter.’”

Further, “The statement said the hackers gained control of employee email accounts for weeks before UC San Diego Health discovered the breach, terminated the accounts, and contacted the FBI. A cybersecurity company is still investigating the incident and UC San Diego Health said the review will finish in September.”

An article from The San Diego Union Tribune notes that “The attack comes not long after the University of California notified thousands that many of its campuses were infiltrated through outdated file transfer software made by Accellion Inc. That breach, however, did not affect UC San Diego Health and did not involve medical information.”

That said, “For Accellion, and now for the new health system breach, the university is offering free credit monitoring and identity theft protection for those who have been affected. Scripps Health, San Diego’s second-largest health system, found itself taking similar steps in late May after notifying the public that a month-long ransomware attack potentially compromised the protected information of more than 147,000 people.”

The notice from UC San Diego Health suggests that “It is always a good idea to remain alert to threats of identity theft or fraud. You can do this by regularly reviewing and monitoring your financial statements, credit reports, and Explanations of Benefits (EOBs) from your health insurers for any unauthorized activity. If you ever suspect that you are the victim of identity theft or fraud, you should contact the company that maintains the account on your behalf or your local police.”

Sponsored Recommendations

Clinical Evaluation: An AI Assistant for Primary Care

The AAFP's clinical evaluation offers a detailed analysis of how an innovative AI solution can help relieve physicians' administrative burden and aid them in improving health ...

From Chaos to Clarity: How AI Is Making Sense of Clinical Documentation

From Chaos to Clarity dives deep into how AI Is making sense of disorganized patient data and turning it into evidence-based diagnosis suggestions that physicians can trust, leading...

Bridging the Health Plan/Provider Gap: Data-Driven Collaboration for a Value-Based Future

Download the findings report to understand the current perspective of provider and health plan leaders’ shift to value-based care—with a focus on the gaps holding them back and...

Exploring the future of healthcare with Advanced Practice Providers

Discover how Advanced Practice Providers are transforming healthcare: boosting efficiency, cutting wait times and enhancing patient care through strategic integration and digital...