Skip to main content
Jump to a category page

UCLA Health says patient information submitted through online appointment forms was disclosed to an outside healthcare provider in a manner inconsistent with its own privacy policies, for well over a year before the pattern was caught.

UCLA Health has notified approximately 94,000 patients of a data breach involving protected health information. According to UCLA Health’s notice letter, the health system determined on July 2, 2026 that patient information had been accessed and disclosed to an outside healthcare provider in a manner inconsistent with UCLA Health’s policies governing protected health information. Secondary reporting on the incident indicates the disclosures were tied to information submitted through UCLA Health’s online appointment forms. UCLA Health reported the breach to the California Attorney General on August 4, 2026.

Source: UCLA Health’s own Notice of Breach of Protected Health Information letter; California Attorney General data-breach notification list (reported 08/04/2026); Becker’s Hospital Review coverage of the incident.

A Disclosure Pattern That Ran for Well Over a Year

This was not a single mistaken disclosure. According to UCLA Health’s California Attorney General filing, the affected disclosures occurred between December 27, 2024 and April 21, 2026, a span of nearly a year and a half. UCLA Health did not determine that these disclosures were happening until July 2, 2026, roughly three months after the pattern’s most recent known instance, and did not report the breach to California regulators until August 4, 2026. UCLA Health has not explained how a misdirected-disclosure pattern went unnoticed for that long.

What Information Was Exposed?

According to UCLA Health’s notice letter, the information involved was contained in patients’ medical records and varied by individual. It may have included:

  • Name
  • Address
  • Date of birth
  • Health insurance information
  • Clinical information, such as referral orders
  • Last four digits of a Social Security number (for a limited number of individuals)

UCLA Health states that full Social Security numbers, financial account numbers, and payment card information were not involved.

How Many People Are Affected?

Approximately 94,000 individuals have been notified, according to secondary reporting on UCLA Health’s notice. UCLA Health’s California Attorney General filing does not itemize a specific count, consistent with the state’s reporting format.

What Is UCLA Health Offering Affected Individuals?

UCLA Health is offering complimentary access to Experian IdentityWorks for 12 months, including a $1,000,000 identity theft insurance policy, credit monitoring, dark web surveillance, and identity restoration support. Affected individuals must enroll by October 31, 2026 at experianidworks.com using the activation code included in their letter, or call 833-745-1349, Monday through Friday, 6 a.m. to 6 p.m. Pacific Time.

Your Information Is at Risk

Health insurance information and clinical details like referral orders can be used to commit medical identity theft, including someone using your insurance to obtain treatment in your name or filing fraudulent claims. For the limited group of patients whose partial Social Security number was also involved, that adds to the risk, since a partial number combined with a name, address, and date of birth can still assist identity thieves. Affected individuals should review statements from their health plan and providers for unfamiliar activity and monitor their credit reports.

Do You Have Legal Options?

Healthcare systems that collect and store protected health information have a legal duty under HIPAA and California law to secure that data and to notify affected patients without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from UCLA Health.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

Who is affected by the UCLA Health data breach?

Approximately 94,000 UCLA Health patients whose information was submitted through online appointment forms and disclosed to an outside healthcare provider between December 27, 2024 and April 21, 2026.

What information was exposed?

Name, address, date of birth, health insurance information, and clinical information such as referral orders, according to UCLA Health’s notice letter. For a limited number of individuals, the last four digits of a Social Security number were also involved. UCLA Health states full Social Security numbers, financial account numbers, and payment card information were not involved.

How did this breach happen?

UCLA Health says patient information was disclosed to an outside healthcare provider in a manner inconsistent with its own privacy policies. Secondary reporting on the incident ties the disclosures to information submitted through UCLA Health’s online appointment forms, rather than to external hacking.

Why did it take so long to catch this?

The disclosures UCLA Health has identified occurred over nearly a year and a half, between December 2024 and April 2026, but UCLA Health did not determine the pattern was happening until July 2026. UCLA Health has not publicly explained how the pattern went unnoticed for that long.

Is UCLA Health offering credit monitoring?

Yes. UCLA Health is offering 12 months of complimentary Experian IdentityWorks, including $1 million in identity theft insurance and credit monitoring, with enrollment required by October 31, 2026.

Do I have a legal claim?

Healthcare systems that collect and store protected health information have a legal duty under HIPAA and California law to secure that data and to notify affected patients without unreasonable delay. If you received a notice letter from UCLA Health, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now