PhysicalTheftCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighContained
CALIFORNIA COLLEGE OF THE ARTS
bd_7d2950008d19fdc7 · schema v1 · pii pii-v1
Full breach record for CALIFORNIA COLLEGE OF THE ARTS →On January 19, 2018, a laptop used by an employee of California College of the Arts was stolen from the employee's vehicle. The device may have contained names, Social Security numbers, dates of birth, subscriber member numbers, and health insurance information for up to 2,581 California residents. The College changed passwords, monitored for device activity, and engaged third-party cybersecurity firms. No evidence of misuse was found. Notices were sent on February 26, 2018, offering one year of credit monitoring.
California clockDiscovered Jan 19, 2018 → Notified Feb 26, 201838d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_55a0e40018036876HHS OCRfiled 2018-02-26Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-134073
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2018
- Raw hash
- 68ab27c4e50b3e27c6663ec84b2849e43bdc3c649edb00e508eee8aeba26023f
Reporting entity
- Name
- CALIFORNIA COLLEGE OF THE ARTSnorm: california college of the arts
Victim entity
- Name
- CALIFORNIA COLLEGE OF THE ARTSnorm: california college of the arts
Incident
- Discovered
- Jan 19, 2018
- Materiality determined
- —
- Notification sent
- Feb 26, 2018
- Affected individuals
- 2,581
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Regulator citations
- Provided notice of this incident to state regulators as requiredProvided notice of this incident to the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 38d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 19, 2018→ Notified: Feb 26, 201838d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.