DisclosureLens
PhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIHealth (basic)Government IDIdentity (basic)MediumContained

Cedars-Sinai Health Systems

bd_b921a7d46f5e1a94 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 23, 2014

Filed

Aug 22, 2014

To disclose

9 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for Cedars-Sinai Health Systems2 incidents on file

Cedars-Sinai Health System reported the theft of an employee's laptop on June 23, 2014. The device, used for clinical laboratory reporting troubleshooting, was stolen in a burglary at the employee's home. Although password-protected, it lacked encryption, potentially exposing temporary files containing patient health information, including medical record numbers, lab results, and some Social Security numbers. Remote access was terminated, and forensic experts reviewed the files. Patients were notified in late August 2014.

California clockDiscovered Jun 23, 2014Notified Aug 29, 201467d CA 60-day late9 weeks discovery → filing

Incident timeline

discovery → filing · 9 weeks / 60 days

Jun 23, 2014

Begins

Jun 23, 2014

Discovered

Aug 22, 2014

Filed

vs. sector median

3 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.