PhysicalTheftCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Cedars-Sinai Health System Defined Benefit Retirement Plan
bd_2f6bc14c5179fb39 · schema v1 · pii pii-v1
Full breach record for Cedars-Sinai Health System Defined Benefit Retirement Plan →Cedars-Sinai Health System reported the theft of an employee's laptop on June 23, 2014. The device contained temporary files with potentially sensitive patient health information, including Social Security numbers, names, demographic data, medical records, and billing information. The investigation confirmed that patient data was stored on the hard drive at the time of the theft. Cedars-Sinai notified law enforcement, retained forensic experts, and offered one year of identity protection services to affected individuals.
California clockDiscovered Jun 23, 2014 → Notified Sep 4, 201473d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_aa09f90ad53bf1bcHHS OCRfiled 2014-09-10Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46547
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 10, 2014
- Raw hash
- ed58cf20dc5b23698bc6089aa06148926ece8c7d59d4b9492fd6c846c12c846a
Reporting entity
- Name
- Cedars-Sinai Health System Defined Benefit Retirement Plannorm: cedars sinai health system defined benefit retirement plan
- Domain
- cedars-sinai.org
Victim entity
- Name
- Cedars-Sinai Health System Defined Benefit Retirement Plannorm: cedars sinai health system defined benefit retirement plan
- Domain
- cedars-sinai.org
Incident
- Discovered
- Jun 23, 2014
- Materiality determined
- —
- Notification sent
- Sep 4, 2014
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- Reported the theft to law enforcement
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 73d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 23, 2014→ Notified: Sep 4, 201473d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.