Castro Valley Health, Inc.
bd_a8cd32e429e8d676 · schema v1 · pii pii-v1
Full breach record for Castro Valley Health, Inc. →Castro Valley Health, Inc. disclosed that patient information was inadvertently transferred to a third-party website (Docker Hub) during 2016-2017. The organization became aware of the incident on April 21, 2020, and promptly removed the data. Affected data included patient names, dates of birth, medical record numbers, and care start dates, but excluded SSNs, financial data, and clinical notes. The company implemented renewed training, security audits, and policy enhancements.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2016
Begins
Apr 21, 2020
Discovered
Jun 8, 2020
Filed
vs. sector median
5 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.