Almeida Law Group is investigating a data breach at UCLA Health. The breach occurred on December 27th, 2024. If you were affected, contact Almeida Law Group.
About UCLA Health
UCLA Health is a comprehensive academic health system and a division of the University of California, Los Angeles, headquartered in Los Angeles, California. It operates five hospitals—Ronald Reagan UCLA Medical Center, UCLA Medical Center Santa Monica, Resnick Neuropsychiatric Hospital, Mattel Children’s Hospital UCLA, and UCLA West Valley Medical Center—along with more than 280 medical practices throughout Southern California. Founded in 1955 and affiliated with the David Geffen School of Medicine at UCLA, it employs approximately 35,500 people and provides primary, specialty, and advanced medical care across the region. Because UCLA Health maintains detailed medical records for its patients, breaches of its systems carry significant risk of health and personal information exposure.
What Happened?
UCLA Health was listed in a California Attorney General sample breach notice. According to that filing and the breach notice sent to affected individuals, on December 27th, 2024, patient protected health information was accessed and disclosed to an outside healthcare provider in a manner inconsistent with UCLA Health’s internal policies governing protected health information. This was not a cyberattack or ransomware event; the notice describes what appears to be an internal policy violation or system configuration error. UCLA Health determined that the disclosure had occurred in July 2025 and filed notice with the California Attorney General on August 4th, 2026. The organization states it has found no evidence that the information was further disclosed or misused beyond the initial improper disclosure.
The data involved varied by individual and may have included name, address, date of birth, health insurance information, and clinical information such as referral orders. For some individuals, the last four digits of a Social Security number were also included. No full Social Security numbers, financial account numbers, or payment card information were involved. UCLA Health says it promptly investigated and deployed additional monitoring and enhanced system controls following the discovery. UCLA Health has a documented history of prior privacy and security incidents, including a 2015 cyberattack that exposed protected health information of approximately 4.5 million patients and resulted in a $7.5 million class action settlement, a $865,000 HHS fine for HIPAA violations tied to employee access of celebrity medical records between 2005 and 2009, and a 2023 incident involving pixel tracking tools that affected approximately 94,000 patients and was investigated for potential class action litigation.
Key Facts at a Glance
- Company or Organization: UCLA Health
- Industry: Healthcare & Social Services (Academic Medical Center / Hospital System)
- Location: Los Angeles, California
- Incident type: Improper disclosure of protected health information to an outside healthcare provider
- Date of breach: December 27th, 2024
- Date breach discovered: July 2025
- Date of consumer notification: August 4th, 2026
- Identity theft protection offered: 12 months of Experian IdentityWorks
- Enrollment deadline: October 31st, 2026
- Prior breach: Yes — 2015 cyberattack (4.5 million affected, $7.5 million settlement); 2005–2009 HIPAA violations ($865,000 fine); 2023 pixel tracking incident (~94,000 affected)
- Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-627637); UCLA Health Breach Notice PDF (https://oag.ca.gov/system/files/EXP_Q1655_UCLE_DBM-5843_L02_SAS_1.pdf); HIPAA Journal (https://www.hipaajournal.com/ucla-health-settles-class-action-data-breach-lawsuit-for-7-5-million/); University of California Health (https://health.universityofcalifornia.edu/patient-care/academic-health-centers/ucla-health)
What Should You Do?
If you received a notice from UCLA Health about this incident, enroll in the complimentary 12 months of Experian IdentityWorks by October 31st, 2026, using the instructions provided in your notice. Because health information was involved, review any Explanation of Benefits statements from your health insurer and check your medical records for services you did not receive. Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion to help prevent unauthorized accounts from being opened in your name. Monitor your credit reports regularly—you can request a free copy from each of the three major bureaus at AnnualCreditReport.com or by calling 1-877-322-8228. If you discover signs of fraud or identity theft, visit IdentityTheft.gov for step-by-step guidance on reporting and recovery.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.