PhysicalTheftCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Cedars-Sinai Health System Defined Benefit Retirement Plan
bd_b921a7d46f5e1a94 · schema v1 · pii pii-v1
Full breach record for Cedars-Sinai Health System Defined Benefit Retirement Plan →Cedars-Sinai Health System reported the theft of an employee's laptop on June 23, 2014. The device, used for clinical laboratory reporting troubleshooting, was stolen in a burglary at the employee's home. Although password-protected, it lacked encryption, potentially exposing temporary files containing patient health information, including medical record numbers, lab results, and some Social Security numbers. Remote access was terminated, and forensic experts reviewed the files. Patients were notified in late August 2014.
California clockDiscovered Jun 23, 2014 → Notified Aug 29, 201467d ✗ CA 60-day late9 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-46348
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2014
- Raw hash
- aba0c2cdb0fb9f744abca3a92dab3729052200f107fb0ec45ca199278992901f
Reporting entity
- Name
- Cedars-Sinai Health System Defined Benefit Retirement Plannorm: cedars sinai health system defined benefit retirement plan
- Domain
- cedars-sinai.org
Victim entity
- Name
- Cedars-Sinai Health System Defined Benefit Retirement Plannorm: cedars sinai health system defined benefit retirement plan
- Domain
- cedars-sinai.org
Incident
- Discovered
- Jun 23, 2014
- Materiality determined
- —
- Notification sent
- Aug 29, 2014
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day late · 67d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 23, 2014→ Notified: Aug 29, 201467d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.