California Department of State Hospitals
bd_c1cfab1260d5fbcf · schema v1 · pii pii-v1
Full breach record for California Department of State Hospitals →The CA Department of State Hospitals (DSH) disclosed that an employee improperly accessed personal and health information of approximately 2,952 employees, former employees, and job applicants. The data included names, addresses, phone numbers, email addresses, social security numbers, dates of birth, and health-related test results. The incident was discovered on March 15, 2021, during an investigation into the employee, who had previously been found to have improperly accessed patient and employee data in February 2021. The employee was placed on administrative leave, and the investigation is ongoing. No evidence of misuse of the compromised information has been found.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_bef01021bc772a9bCalifornia State AGfiled 2021-03-17(19d gap)Candidate
- bd_cf89708cf713e481HHS OCRfiled 2021-03-17(19d gap)Verified
- bd_f0d4f93fd7d4c2f2California State AGfiled 2021-05-11(36d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539698
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2021
- Raw hash
- f7ffc653e936f556c400c5b25b6e412ca24b0d7d82c8fb582742c02f2112541d
Reporting entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
- Domain
- dsh.ca.gov
Victim entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
- Domain
- dsh.ca.gov
Incident
- Discovered
- Mar 15, 2021
- Materiality determined
- —
- Notification sent
- Apr 5, 2021
- Affected individuals
- 2,952
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified United States Health and Human Services, Office of Civil RightsNotified California Office of Information SecurityNotified California Office of Health Information IntegrityNotified California Highway PatrolNotified California Department of Public HealthNotified California Attorney General’s Office
- Initial access
- insider_action
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 15, 2021→ Notified: Apr 5, 202121d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.