DisclosureLens
MisuseHealthcareHealthcareData MishandlingCustomer Data InvolvedEmployee Data InvolvedPHIHealth (basic)Identity (basic)Government IDMediumContained

Family Health Centers of San Diego

bd_29e5ae363041c3fb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

May 12, 2026

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

66%
Full breach record for Family Health Centers of San Diego

Family Health Centers of San Diego reported that a physician employee sent personal health information to their personal email address. The incident window is listed as December 15, 2021, to February 27, 2026. Affected data includes names, medical record numbers, contact info, dates of birth, and medical information. The physician was terminated, access revoked, and legal action initiated. Credit monitoring is offered.

California clockConsumers notified Apr 30, 2026AG copy submitted May 12, 202612d CA AG copy ≤15d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Dec 15, 2021

Begins

May 12, 2026

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRMay 12 · first
California State AGMay 12 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.