CALIFORNIAPhysicalHealthcareGovernmentHealthcareLossCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTMediumResolved
Ventura County Health Care Agency
bd_b9627d6d127d6d23 · schema v1 · pii pii-v1
Full breach record for Ventura County Health Care Agency →Ventura County Health Care Agency (CA) reported to HHS on 2015-05-06 a Loss affecting 1,339 individuals. A backpack containing documents for 1,399 patients was left at an elementary school after it was stolen from an employee's car. PHI involved included names, balances owed, and internal account numbers. All files were intact. The CE sanctioned the responsible workforce member, retrained staff, and provided OCR with written assurance of refresher HIPAA Privacy reminders. Breached information was on Paper/Films.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,339 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 6, 2015
- Raw hash
- 51ca3c9081b60d54a61b7f5235bb7acfa4b11f7a514827e4fd7bbadc938c028c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Ventura County Health Care Agencynorm: ventura county health care agency
- Industry
- Health Care Services
Victim entity
- Name
- Ventura County Health Care Agencynorm: ventura county health care agency
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,339
- Data types
- HEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- External
- Regulator citations
- HHS OCR notifiedHIPAA Notice of Privacy Practices Policy submitted to OCRWritten assurance of refresher training provided to OCR
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.