DisclosureLens
AccidentalHealthcareGovernmentHealthcareMisconfigurationEmployee Data InvolvedGovernment IDIdentity (basic)EmploymentMediumResolved

California Department of State Hospitals

bd_526a688db41cadfc · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 8, 2013

Filed

May 24, 2013

To disclose

16 days

Affected

Not disclosed

Confidence

66%
Full breach record for California Department of State Hospitals3 incidents on file

The California Department of State Hospitals (DSH) disclosed that an employee roster containing confidential personal information, including Social Security numbers, names, position numbers, titles, and Bargaining Units, was mistakenly placed on the Patton State Hospital intranet website. The data was accessible for approximately 6 hours on May 8, 2013, before the error was discovered and corrected. DSH reviewed access logs and interviewed employees, concluding that only a small number of unauthorized employees viewed the data and further disclosure is unlikely. The incident involved employee data only.

Incident timeline

discovery → filing · 16 days

May 8, 2013

Begins

May 8, 2013

Discovered

May 24, 2013

Filed

vs. sector median

10 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.