California Department of State Hospitals
bd_bef01021bc772a9b · schema v1 · pii pii-v1
Full breach record for California Department of State Hospitals →3 incidents on fileAn employee at the CA Department of State Hospitals (DSH)-Atascadero improperly accessed patient and employee data servers using legitimate IT credentials. The incident involved the unauthorized access of names, COVID-19 test results, and health information for approximately 1,415 patients and 617 employees. The breach occurred between November 6, 2020, and February 5, 2021, and was discovered on February 25, 2021, during an annual access rights review. The employee was placed on administrative leave, and the incident was reported to multiple state and federal regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 6, 2020
Begins
Feb 25, 2021
Discovered
Mar 17, 2021
Filed
vs. sector median
9 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_cf89708cf713e4812021-03-17Verified
- California State AGbd_c1cfab1260d5fbcf2021-04-05 · +19dCandidate
- California State AGbd_f0d4f93fd7d4c2f22021-05-11 · +55dCandidate
Filing propagation · 4 filings
View merged incident ↗Pattern: first filing Mar 17 (CA), last May 11 (CA) — a 55-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.