California Department of Corrections and Rehabilitation
bd_97fde22c616799e5 · schema v1 · pii pii-v1
Full breach record for California Department of Corrections and Rehabilitation →8 incidents on fileCalifornia Department of Corrections and Rehabilitation (CDCR) notified individuals of unauthorized access to a file-sharing platform. Suspicious activity was discovered in January 2022, dating back to December 2021. An investigation confirmed an unauthorized user accessed the system, but no evidence of data copying or downloading was found. Affected data included names, addresses, phone numbers, emails, dates of birth, and medical information (COVID-19 testing, mental health, substance use treatment). No SSNs or financial data were involved. CDCR shut down the platform and migrated to a new system with enhanced security.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 21, 2021
Begins
Jan 1, 2022
Discovered
Aug 22, 2022
Filed
vs. sector median
+22 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_9563e209b3098d612022-08-22Verified
Filing propagation · 2 filings
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.