DisclosureLens
AccidentalHealthcareGovernmentHealthcareMisconfigurationPublishing ErrorEmployee Data InvolvedIdentity (basic)Government IDEmploymentMediumResolved

California Correctional Health Care Services

bd_a30ddf1b0ba50a90 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 24, 2022

Filed

Nov 18, 2022

To disclose

25 days

Affected

Not disclosed

Confidence

66%
Full breach record for California Correctional Health Care Services13 incidents on file

California Correctional Health Care Services (CCHCS) disclosed an incident where employee personal information, including full names and truncated Social Security Numbers (last four digits), was improperly posted on an internal nursing shared drive and a bulletin board at the California Health Care Facility between October 12 and October 24, 2022. The data was used for a Psychiatric Inpatient Program Seniority Listing. Upon discovery on October 24, 2022, CCHCS removed the lists, replaced them with non-PII identifiers, and mandated privacy training for involved staff. The incident is classified as an error involving employee data.

Incident timeline

undetected · 12 days
discovery → filing · 25 days

Oct 12, 2022

Begins

Oct 24, 2022

Discovered

Nov 18, 2022

Filed

vs. sector median

8 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.