MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPHIHEALTH_BASICMediumActive
California Department of State Hospitals
bd_bef01021bc772a9b · schema v1 · pii pii-v1
Full breach record for California Department of State Hospitals →CA Department of State Hospitals (DSH) disclosed a breach at DSH-Atascadero involving an IT employee who improperly accessed patient and employee records. The incident, discovered on Feb 25, 2021, compromised PHI including names and COVID-19 test results for approximately 1,415 patients and 617 employees (total 2,032). The employee was placed on administrative leave. No SSN or financial data was involved. DSH notified HHS OCR, CA state agencies, and law enforcement.
California clockDiscovered Feb 25, 2021 → Notified Mar 17, 202120d ✓ CA 60-day OK20 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_cf89708cf713e481HHS OCRfiled 2021-03-17Verified
- bd_c1cfab1260d5fbcfCalifornia State AGfiled 2021-04-05(19d gap)Candidate
- bd_f0d4f93fd7d4c2f2California State AGfiled 2021-05-11(55d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539211
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2021
- Raw hash
- 5ad34db3740df0d9d95f95bc2780ea08f2045d8f60dbd8514a88021ab49162b6
Reporting entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
- Domain
- dsh.ca.gov
Victim entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
- Domain
- dsh.ca.gov
Incident
- Discovered
- Feb 25, 2021
- Materiality determined
- Mar 17, 2021
- Notification sent
- Mar 17, 2021
- Affected individuals
- 2,032
- Data types
- PHIHEALTH_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified HHS Office of Civil RightsNotified California Office of Information SecurityNotified California Office of Health Information IntegrityNotified California Highway PatrolNotified California Department of Public HealthNotified California Attorney General’s Office
- Initial access
- insider_action
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 25, 2021→ Notified: Mar 17, 202120d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.