Hackers accessed computers with sensitive records of 4.5 million people


In July 2015, the university disclosed a bad actor had accessed parts of their network that contained the personal information of 4.5 million individuals. At that time it was the fourth-biggest healthcare data breach of all time. There were "indications" that led the company to believe that the attacker may have initiated the network access as early as September 2014.

The potentially exposed information included names, addresses, dates of birth, social security numbers, medical record numbers and some medical information such as medical condition, medications, procedures and test results.

In March 2019, the university reached a settlement related to this incident.

In July 2023, it was reported that the governing board of the university had filed a lawsuit against their insurer alleging breach of contract and seeking unspecified damages.

Book a consultation

Want to discuss this case? You can purchase a 30 minute conference call with our analysts to discuss this case and the implications it has for your organisation. Just select the time and date that works for you:


  • The University of California, Los Angeles
  • UCLA

We've done the analysis so you can make the decisions

When purchasing a minimum of 5 Case Studies
$699.99 if buying less than 5.

  • Detailed cause & effect analysis
  • Lessons learnt catalogued
  • Preventive controls extracted
Add to Cart
Heads up! Want to try before you buy? You can download our FREE demo case study here