UC Davis Health Data Breach
UC Davis Health Email Breach Affects 3,201 Patients
What happened in the UC Davis Health data breach?
The UC Davis Health data breach was reported on July 28, 2023 and affected 3,201 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
UC Davis Health Breach Details
UC Davis Health Email Security Incident
On July 28, 2023, UC Davis Health, a major academic medical center in California, reported a significant data breach affecting 3,201 individuals. The breach resulted from unauthorized access to email systems, a common vector for healthcare data compromise. This incident represents a serious breach of patient privacy and triggered mandatory notification requirements under the Health Insurance Portability and Accountability Act (HIPAA). The email systems compromised likely contained sensitive patient health information accumulated through routine clinical operations, patient communications, and administrative functions.
Company Response
UC Davis Health discovered the unauthorized access to its email infrastructure and initiated an immediate investigation to determine the scope and nature of the compromise. Upon discovery, the organization took steps to secure affected systems, preserve evidence, and conduct a thorough forensic analysis to identify what information may have been accessed by unauthorized parties. The organization notified affected individuals as required by HIPAA Breach Notification Rule, which mandates notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured protected health information (PHI). UC Davis Health also reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), as required for breaches affecting 500 or more residents of a state or jurisdiction.
Specific Details
Email systems represent particularly vulnerable entry points in healthcare IT infrastructure because they typically contain extensive patient communications, clinical notes, appointment information, and administrative records. Hacking incidents targeting email often involve credential compromise, phishing attacks, exploitation of unpatched vulnerabilities, or brute-force attacks against authentication systems. Once attackers gain access to email accounts, they can potentially access years of accumulated correspondence and attachments containing sensitive patient data. The fact that this breach was classified as a "hacking/IT incident" rather than a simple loss or theft suggests deliberate unauthorized access, likely through technical exploitation rather than physical theft of devices or documents. Email breaches of this nature typically result in exposure of whatever information was stored in affected mailboxes, which in a healthcare setting commonly includes patient names, medical record numbers, dates of birth, insurance information, and clinical details discussed in patient-provider communications.
Organizational Context
UC Davis Health is a major academic medical center and health system serving Northern California, affiliated with the University of California, Davis School of Medicine. As an academic medical center, UC Davis Health operates multiple facilities including a primary teaching hospital, specialty clinics, and outpatient services. The organization serves a diverse patient population across a large geographic region and maintains extensive electronic health records and communications systems. Academic medical centers typically handle complex patient cases and maintain detailed clinical documentation, making them attractive targets for cybercriminals seeking valuable health information. The scale of UC Davis Health's operations means that email systems likely process thousands of patient-related communications daily across multiple departments and clinical specialties.
Patient Impact and Notifications
The breach affected 3,201 individuals whose information may have been accessed through compromised email accounts. These patients likely included individuals who had communicated with UC Davis Health providers via email, received appointment notifications, or had their information referenced in clinical communications. The specific types of personal health information potentially exposed would depend on the content of individual email accounts, but typically include names, contact information, dates of birth, medical record numbers, insurance details, and clinical information discussed in patient-provider communications. UC Davis Health provided notification to affected individuals in accordance with HIPAA requirements, informing them of the breach, the types of information potentially compromised, and recommended steps to protect themselves. The organization also offered credit monitoring or identity theft protection services to affected individuals, a common remedial measure following healthcare data breaches.
Industry Context and HIPAA Implications
Email-based breaches represent a significant and growing threat in healthcare cybersecurity. According to healthcare breach statistics, email compromise incidents account for a substantial portion of reported healthcare data breaches, often resulting from phishing, credential theft, or exploitation of email server vulnerabilities. HIPAA's Breach Notification Rule requires covered entities and business associates to notify affected individuals, the media (for breaches affecting 500+ residents of a state), and HHS OCR when unsecured PHI is accessed or acquired by unauthorized persons. The rule defines "unsecured PHI" as protected health information that is not rendered unusable through encryption or destruction. Healthcare organizations are required to conduct risk assessments to determine whether a breach has likely compromised the privacy or security of PHI. The 3,201-person threshold in this incident triggered state-level media notification requirements, elevating public awareness of the breach. Similar email-based breaches have affected numerous healthcare organizations nationwide, highlighting the need for strong email security controls including multi-factor authentication, advanced threat detection, employee security training, and regular security assessments. UC Davis Health's response demonstrates the healthcare industry's ongoing challenge in protecting patient information in an increasingly sophisticated threat environment.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the UC Davis Health Breach
Monitor credit reports and financial accounts closely for signs of unauthorized activity. Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized credit applications in your name.
Review explanation of benefits (EOB) statements and healthcare bills carefully for any services you did not receive or appointments you did not attend. Contact your insurance provider and healthcare providers immediately if you identify suspicious activity.
Change passwords for any online healthcare portals, email accounts, and financial accounts, using strong, unique passwords (minimum 12 characters with mixed case, numbers, and symbols). Enable multi-factor authentication wherever available.
Be vigilant against phishing emails and suspicious communications claiming to be from UC Davis Health or your insurance provider. Do not click links or download attachments from unsolicited emails; instead, contact organizations directly using phone numbers from official websites.
Consider enrolling in the identity theft protection or credit monitoring services offered by UC Davis Health as part of their breach response, if available. These services typically provide monitoring, alerts, and recovery assistance.
Document all communications related to the breach, including notification letters and any suspicious activity you discover. Keep records of steps taken to protect your information.
Contact the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and file a report with local law enforcement if you discover evidence of fraud or identity theft.
Request a free credit report from AnnualCreditReport.com and review it for accounts or inquiries you do not recognize. You are entitled to one free report annually from each bureau.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California