DisclosureLens
MisuseHealthcareHealthcarePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedPHIHealth (basic)Identity (basic)Government IDMediumResolved

California Pacific Medical Center

bd_59a42b43d70adf9e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 10, 2014

Filed

Jan 23, 2015

To disclose

15 weeks

Affected

844state residents only

Linked

2 filings

Confidence

66%
Full breach record for California Pacific Medical Center

California Pacific Medical Center (CPMC) notified 844 patients after an audit revealed a pharmacist employee accessed their records without a business or treatment purpose between October 2013 and October 2014. The accessed data included patient demographics, last four digits of SSN, clinical information, and prescription details. CPMC terminated the employee and notified affected individuals. No evidence of malicious intent or unauthorized sharing was found.

California clockDiscovered Oct 10, 2014Notified Oct 21, 201411d CA 60-day OK15 weeks discovery → filing

Incident timeline

undetected · 374 days
discovery → filing · 15 weeks / 105 days

Oct 1, 2013

Begins

Oct 10, 2014

Discovered

Jan 23, 2015

Filed

vs. sector median

+3 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRJan 23 · first
California State AGJan 23 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.