AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Castro Valley Health, Inc.
bd_a8cd32e429e8d676 · schema v1 · pii pii-v1
Full breach record for Castro Valley Health, Inc. →Castro Valley Health, Inc. disclosed a data security incident involving the inadvertent transfer of patient information to a third-party website (Docker Hub) between 2016 and 2017. The company discovered the breach on April 21, 2020, and removed the data. Affected data included patient names, dates of birth, medical record numbers, and therapist details. No clinical notes, SSNs, or financial data were involved. The organization implemented enhanced security audits, policy updates, and employee training.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190727
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2020
- Raw hash
- 7656d58737977885da54568ff31127712ec8995f9a2476cfd17c7ef62aef8b00
Reporting entity
- Name
- Castro Valley Health, Inc.norm: castro valley health
Victim entity
- Name
- Castro Valley Health, Inc.norm: castro valley health
Incident
- Discovered
- Apr 21, 2020
- Materiality determined
- May 29, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.