DisclosureLens
AccidentalGovernmentGovernmentMisconfigurationEmployee Data InvolvedIdentity (basic)Health (basic)EmploymentLowActive

Los Angeles Fire Department

bd_4a14cc1692e9f447 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 14, 2021

Filed

Sep 1, 2021

To disclose

7 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Los Angeles Fire Department2 incidents on file

The County of Los Angeles Fire Department disclosed that a County employee created a website intended for EMS staff to obtain proof of COVID vaccinations. The website was misconfigured, allowing unauthorized users to view personal information including names, dates of birth, employee IDs, and vaccination details. The incident was discovered on July 14, 2021, and the website was immediately taken down. The investigation is ongoing.

California clockDiscovered Jul 14, 2021Notified Aug 12, 202129d CA 60-day OK7 weeks discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 7 weeks / 49 days

Jul 13, 2021

Begins

Jul 14, 2021

Discovered

Sep 1, 2021

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.