UCSF home page UCSF home About UCSF Search UCSF UCSF Medical Center

Security Incident

Report Problem
Lost/Stolen Device

VPN

Login to vpn@ucsf
VPN Help

image of phone Help

blank Login to help@ucsf
blank email us
blank Call (415) 514-4100,
blank Option 2




Advanced Search
Recent Changes

California Senate Bill 1386 (SB1386)

Statement

UCSF complies with the provisions of California Privacy Legislation, California Senate Bill 1386 (SB1386), requiring notification to California residents regarding any breach to the security of a computing system where there is a reasonable belief that an unauthorized person has acquired their unencrypted personal information.

The data covered by this law is an individual's first name or first initial and last name in combination with any one or more of the following:

On September 30, 2008, Governor Schwarzenegger approved legislation that established specific reporting requirements regarding the unlawful or unauthorized access to, use, or disclosure of patient medical information, and that increased financial penalties for violations. The new requirements and penalties have been added to the California Health and Safety Code and took effect on January 1, 2009. 

University Policy has been updated to address these additions to California Code: Business and Finance Bulletin IS-3, "Electronic Information Security," contains the University policy for notification in cases of information security breaches. Section III.D has been updated to include the new reporting requirement for unlawful or unauthorized access to, use, or disclosure of patient medical information, as well as to ensure more consistent, systemwide incident-response processes. 

Mitigation or notification requirements may differ, depending on the federal or state statues, the nature of the information at risk in the event of a security breach, or contractual agreement. For example:

The updated bulletin is posted on the Web at http://www.ucop.edu/ucophome/policies/bfb/bfbis.html

If you have a concern regarding SB1386 at UCSF please contact the designated individual noted below.

To Report a Breach

To report any information security problems, potential problems or suspected unauthorized access to unencrypted personal information. you may do one of the following:

For more information, please go to http://security.ucsf.edu/EIS/IncidentReporting.html

Designated Individual

The designated individual for UCSF regarding SB1386 is:

Michael Kamerick
Interim UCSF Information Security Officer
415-476-3580
security@its.ucsf.edu

UCSF OAAIS
Office of Academic and Administrative Information Systems
Enterprise Information Security
Box 0707
San Francisco, CA 94143-0707

Resources

http://www.privacyprotection.ca.gov/leg2002.htm#pagetop

http://www.ucop.edu/ucophome/policies/bfb/is3.pdf
(Adobe Acrobat Reader)

Return to Policies, Procedures, and Guidelines page.

Please tell us what you think of our website