DisclosureLens
AccidentalHealthcareHealthcareMisconfigurationPublishing ErrorCustomer Data InvolvedDelayed DiscoveryPHIHealth (basic)Identity (basic)LowContained

Castro Valley Health, Inc.

bd_a8cd32e429e8d676 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 21, 2020

Filed

Jun 8, 2020

To disclose

7 weeks

Affected

Not disclosed

Confidence

64%
Full breach record for Castro Valley Health, Inc.

Castro Valley Health, Inc. disclosed that patient information was inadvertently transferred to a third-party website (Docker Hub) during 2016-2017. The organization became aware of the incident on April 21, 2020, and promptly removed the data. Affected data included patient names, dates of birth, medical record numbers, and care start dates, but excluded SSNs, financial data, and clinical notes. The company implemented renewed training, security audits, and policy enhancements.

California clockDiscovered Apr 21, 2020Notified May 29, 202038d CA 60-day OK7 weeks discovery → filing

Incident timeline

undetected · 1572 days
discovery → filing · 7 weeks / 48 days

Jan 1, 2016

Begins

Apr 21, 2020

Discovered

Jun 8, 2020

Filed

vs. sector median

5 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.