4.5 Million-Victims Hit in UCLA Health Hack

The multi-site health division of the University of California Los Angeles (UCLA) suffered an attack that could infect as many as 4.5 million people. The university went public with the news that hackers had broken into the network of UCLA Health, which maintains patient information, such as names, addresses, dates of birth, Social Security numbers, medical record numbers, Medicare and health plan ID numbers and medical information.

So far forensic experts said they have seen no evidence that the cyber criminals have looked at or acquired any of the data. However, the investigation, which includes the Federal Bureau of Investigation, continues.

The case goes back to October 2014, when UCLA Health first detected suspicious activity in its network and began the investigation with the help of the FBI. By May 5, 2015, the health system had determined that the attackers had accessed parts of its network and may have had access as early as September 2014. On July 17 the institution began notifying those people whose information was maintained on the servers.

The university is also doing an investigation of computer systems across the entire campus, which serves about 29,000 students. UCLA Health runs four hospitals and numerous clinics.

To mitigate risk, the university is informing those who may have been victims that they can request 12 months of identity theft recovery and restoration services and additional health care identity protection tools. Also, those whose Social Security number or Medicare identification number was stored on the affected parts of the network will receive 12 months of credit monitoring. The services are being provided at no cost.

The university has also set up a Web site and phone hotline to answer questions.

"Patient confidentiality and the protection of personal information are critically important to UCLA Health. We sincerely regret the impact this attack may have on affected individuals and have dedicated significant resources to assist members of our UCLA community who will have questions and concerns about how this attack may potentially affect them personally," wrote Chancellor Gene Block in a letter to the campus community. "Please know that UCLA Health is committed to the safeguarding of patient information. We take this attack very seriously and are working diligently to prevent similar attacks in the future."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • InCommon Academy in action with an Advance CAMP unconference activity at the Internet2 Technology Exchange

    Community-Driven IAM Learning with Internet2's InCommon Academy

    Internet2's InCommon Academy Director Jean Chorazyczewski examines how the academy's community-driven identity and access management learning opportunities support CIOs, IT leaders, and their IAM teams in R&E.

  • businessman juggling cubes

    Anthology Restructures, Focuses on Teaching and Learning Business

    Anthology has announced a strategic restructuring, divesting its Enterprise Operations, Lifecycle Engagement, and Student Success businesses and filing for Chapter 11 bankruptcy in an effort to right-size its finances and focus on its core teaching and learning products.

  • Jasper Halekas, instrument lead for the Analyzer for Cusp Electrons (ACE), checks final calibration. ACE was designed and built at the University of Iowa for the TRACERS mission.

    TRACERS: The University of Iowa Leads NASA-Funded Space Weather Research with Twin Satellites

    Working in tandem, the recently launched TRACERS satellites enable new measurement strategies that will produce significant data for the study of space weather. And as lead institution for the mission, the University of Iowa upholds its long-held value of bringing research collaborations together with academics.

  • Hand holding a stylus over a tablet with futuristic risk management icons

    Why Universities Are Ransomware's Easy Target: Lessons from the 23% Surge

    Academic environments face heightened risk because their collaboration-driven environments are inherently open, making them more susceptible to attack, while the high-value research data they hold makes them an especially attractive target. The question is not if this data will be targeted, but whether universities can defend it swiftly enough against increasingly AI-powered threats.