Loma Linda and UCLA Health flag separate patient data exposures

Two California academic medical centers disclose fresh incidents, one tied to an external AI platform.

MedRisk Staff
By
2 Min Read

Two California academic medical centers have filed fresh breach notifications with the state attorney general, documenting separate patient data exposures that point to very different failure points, one rooted in AI-assisted research and the other in routine care coordination.

Loma Linda’s filing leads with what the exposed dataset did not contain: no complete treatment records, no Social Security numbers, no financial or insurance information. What investigators did find were patient identifiers, such as medical record numbers and birth dates, along with limited clinical detail connected to orthopedic care. The records came from an Institutional Review Board-approved research study and were placed on an external AI platform at some point during that work. The affected count has not been disclosed, and the organization says it is reviewing its policies, procedures, and workforce training around external technologies such as AI platforms.

The records involved in the UCLA case date back more than a year, with the exposure window running from December 27, 2024 through April 21, 2026, and include names, birth dates, health insurance details, and clinical information such as referral orders. UCLA Health’s review, completed July 2, 2026, found the data had been shared in a way its own policies and HIPAA rules do not permit. The recipient was an outside healthcare provider, and for a limited number of individuals the exposure also included the last four digits of Social Security numbers. The health system says it has added controls and monitoring since the finding and has no indication of actual or attempted misuse.

The two notices, both filed with the California Attorney General, show how research workflows and routine care coordination can leak protected health information outside expected channels. Health systems reviewing AI use should inventory which datasets touch external platforms and confirm business associate coverage before upload.

Share This Article