UCLA Health Data Breach Investigation

Written by 
Published on:
August 6, 2026
Updated on:
August 6, 2026

UCLA Health has begun notifying patients of a new data security incident involving their protected health information. The notice, filed with the California Attorney General's office, describes unauthorized access to patient records that UCLA Health says was inconsistent with its own internal policies governing protected health information. For patients receiving this letter, it raises real questions about how their medical records were handled and what steps they can take next. Contact our data breach attorneys to learn more.

What happened at UCLA Health?

According to the breach notification letter, UCLA Health determined that certain patient information was accessed in a manner that violated the health system's own policies for handling protected health information. The notice does not describe this as an external hacking event. Instead, it centers on access that should not have occurred under UCLA Health's internal data governance rules.

UCLA Health has stated that it has no evidence at this time that the information was further used, disclosed, or misused. The health system says it has since taken additional steps, including enhanced monitoring and system controls, in response to the incident.

What information was involved

Per the official notice, the information affected varied by individual and may have included:

  • Full name and address
  • Date of birth
  • Health insurance information
  • Clinical information, such as referral orders
  • For some individuals, the last four digits of a Social Security number

What UCLA Health is offering

Affected individuals are being offered 12 months of complimentary access to Experian IdentityWorks, which includes credit monitoring, internet and dark web surveillance, and identity restoration support. Patients wishing to enroll must do so by the deadline stated in their individual notification letter. UCLA Health has also stated that any patient who suspects fraudulent use of their information can work directly with an Experian agent to investigate and resolve those issues.

Why this incident matters

Unauthorized access to protected health information, even without evidence of external misuse, can still carry consequences for patients. Medical records, referral information, and partial identification numbers can be pieced together with other data to enable identity theft or medical fraud. Healthcare providers are required under HIPAA and California law to maintain reasonable administrative and technical safeguards to prevent exactly this kind of unauthorized access. When those safeguards fail, patients are entitled to understand what happened and what recourse may be available to them.

Why work with The Lyon Firm

Data breach cases involving healthcare providers move quickly and require careful review of the specific facts involved. The Lyon Firm has experience evaluating data breach claims and holding organizations accountable when patient information is not properly protected. Our attorneys have filed dozens of data privacy class actions in California and nationwide. We can help you:

  • Determine whether your specific information was part of this incident
  • Understand your rights and potential legal options under California and federal law
  • Take practical steps to protect your identity going forward

If you received a breach notification letter from UCLA Health, contact The Lyon Firm today for a free and confidential case review.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.