DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedPHIIdentity (basic)Health (basic)LowResolved

SHIELDS For Families

bd_df955168bc6b05a0 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Apr 26, 2012

To disclose

Affected

961

Confidence

94%
Full breach record for SHIELDS For Families

On February 27, 2012, a computer server was stolen from SHIELDS For Families, a California-based healthcare provider. The server contained electronic protected health information (ePHI) of 961 individuals, including names, addresses, ZIP codes, birth dates, and referral information. The covered entity notified HHS, affected individuals, and the media. Remediation included relocating the replacement server to a locked, secured office, broad IT infrastructure improvements, a revised security program, and workforce retraining. OCR obtained assurances that corrective actions were implemented.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Feb 27, 2012

Begins

Apr 26, 2012

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed961 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.