ST. JOSEPH HEALTH SYSTEM
bd_0dece17688487427 · schema v1 · pii pii-v1
Full breach record for ST. JOSEPH HEALTH SYSTEM →4 incidents on fileSt. Joseph Health System (CA) reported to HHS OCR on 2012-02-15 an Unauthorized Access/Disclosure affecting 12,234 individuals (HHS portal count; OCR investigation found 31,800 individuals actually exposed). ePHI stored on a network server was publicly accessible via internet search engines (e.g. Google) from Feb 1, 2011 to Feb 13, 2012, due to default file-sharing application settings left unconfigured. Data exposed included patient names, health statuses, diagnoses, and demographics. SJH settled with OCR for $2,140,500 and agreed to a corrective action plan.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 1, 2011
Begins
Feb 14, 2012
Discovered
Feb 15, 2012
Filed
vs. sector median
11 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCR enforcementbd_7c07ec9f136d4f6b2016-10-17 · +1706dVerified by operator
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Feb 15 (CA), last Oct 17 — a 1706-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.