CalOptima
bd_3cb594a1301d2dfa · schema v1 · pii pii-v1
Full breach record for CalOptima →3 incidents on fileOn August 17, 2016, a departing CalOptima employee downloaded protected health information, including names, demographic data, and social security numbers for some members (including minors), to an unencrypted USB flash drive. The drive was returned to CalOptima. The organization is investigating the contents and does not believe the information was shared. CalOptima is offering credit/identity monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 17, 2016
Begins
Oct 14, 2016
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.