SAY San Diego
bd_11fab88d330032d8 · schema v1 · pii pii-v1
Full breach record for SAY San Diego →SAY San Diego, a California healthcare provider, reported to HHS on 2017-12-22 a Loss affecting 1,272 individuals. On October 27, 2017, the CE was notified that a citizen had returned paper files containing PHI found in a filing cabinet purchased from a salvage store. Files related to youth participants in a dual diagnosis program (Jan–Jun 2013) included clinical and demographic information. The CE notified individuals, media, and HHS, offered free identity monitoring, revised its PHI disposal policy, and provided additional workforce training following OCR investigation.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2013
Begins
Oct 27, 2017
Discovered
Dec 22, 2017
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_c9016888c593e70e2017-12-28 · +6dCandidate
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing Dec 22 (CA), last Dec 28 (CA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.