DisclosureLens
AccidentalMisconfigurationEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)MediumResolved

Corovan Anywhere

bd_4d023924e41e2c80 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 17, 2017

Filed

Jan 18, 2018

To disclose

13 weeks

Affected

733state residents only

Confidence

64%
Full breach record for Corovan Anywhere

Corovan Corporation disclosed that files containing employee names, addresses, Social Security numbers, and health insurance information were temporarily browsable via Google search due to a server misconfiguration between September 14-18, 2017. The company discovered the issue on October 17, 2017, and notified approximately 733 California residents in January 2018. No evidence of data misuse was found.

California clockDiscovered Oct 17, 2017Notified Jan 16, 201891d CA 60-day late13 weeks discovery → filing

Incident timeline

undetected · 33 days
discovery → filing · 13 weeks / 93 days

Sep 14, 2017

Begins

Oct 17, 2017

Discovered

Jan 18, 2018

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed733 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.