
UCLA Health has begun notifying patients of a new data security incident involving their protected health information. The notice, filed with the California Attorney General's office, describes unauthorized access to patient records that UCLA Health says was inconsistent with its own internal policies governing protected health information. For patients receiving this letter, it raises real questions about how their medical records were handled and what steps they can take next. Contact our data breach attorneys to learn more.
According to the breach notification letter, UCLA Health determined that certain patient information was accessed in a manner that violated the health system's own policies for handling protected health information. The notice does not describe this as an external hacking event. Instead, it centers on access that should not have occurred under UCLA Health's internal data governance rules.
UCLA Health has stated that it has no evidence at this time that the information was further used, disclosed, or misused. The health system says it has since taken additional steps, including enhanced monitoring and system controls, in response to the incident.
Per the official notice, the information affected varied by individual and may have included:
Affected individuals are being offered 12 months of complimentary access to Experian IdentityWorks, which includes credit monitoring, internet and dark web surveillance, and identity restoration support. Patients wishing to enroll must do so by the deadline stated in their individual notification letter. UCLA Health has also stated that any patient who suspects fraudulent use of their information can work directly with an Experian agent to investigate and resolve those issues.
Unauthorized access to protected health information, even without evidence of external misuse, can still carry consequences for patients. Medical records, referral information, and partial identification numbers can be pieced together with other data to enable identity theft or medical fraud. Healthcare providers are required under HIPAA and California law to maintain reasonable administrative and technical safeguards to prevent exactly this kind of unauthorized access. When those safeguards fail, patients are entitled to understand what happened and what recourse may be available to them.
Data breach cases involving healthcare providers move quickly and require careful review of the specific facts involved. The Lyon Firm has experience evaluating data breach claims and holding organizations accountable when patient information is not properly protected. Our attorneys have filed dozens of data privacy class actions in California and nationwide. We can help you:
If you received a breach notification letter from UCLA Health, contact The Lyon Firm today for a free and confidential case review.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: