MisuseData MishandlingData ExfiltratedEmployee Data InvolvedCustomer Data InvolvedDelayed DiscoveryPIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
HILLSIDES
bd_ad3ca247b330def1 · schema v1 · pii pii-v1
Full breach record for HILLSIDES →Hillsides, a California-based social services organization, disclosed that an employee sent internal spreadsheets containing PII (names, SSNs, addresses, phone numbers) and PHI (client names, birth dates, treatment data) to a personal email account between October 2014 and October 2015. The employee was terminated. Data was sent unencrypted. No evidence of further misuse was found, but notification was sent to affected staff and clients.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59475
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 31, 2015
- Raw hash
- 23aa34b10847be4355c38ce4c9c57b8b6533e3d3185ecb7c1b94110f3141d23e
Reporting entity
- Name
- HILLSIDESnorm: hillsides
Victim entity
- Name
- HILLSIDESnorm: hillsides
Incident
- Discovered
- Dec 8, 2015
- Materiality determined
- Dec 30, 2015
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.