California Department of State Hospitals
bd_f0d4f93fd7d4c2f2 · schema v1 · pii pii-v1
Full breach record for California Department of State Hospitals →The California Department of State Hospitals (DSH) discovered on April 13, 2021, that an employee improperly accessed personal and health information of approximately 299 individuals, including employees, former employees, and job applicants. The compromised data included names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, driver's license numbers, immigration information, and health information related to employment. DSH placed the employee on administrative leave, is cooperating with law enforcement, and has notified relevant regulatory bodies including HHS OCR and the California Attorney General. The investigation is ongoing.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c1cfab1260d5fbcfCalifornia State AGfiled 2021-04-05(36d gap)Candidate
- bd_bef01021bc772a9bCalifornia State AGfiled 2021-03-17(55d gap)Candidate
- bd_cf89708cf713e481HHS OCRfiled 2021-03-17(55d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540778
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 11, 2021
- Raw hash
- a2f804c6fd85518fb9c485909974670865375daa36df96ba4dc5f88254ccc8ac
Reporting entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
Victim entity
- Name
- California Department of State Hospitalsnorm: california department of state hospitals
Incident
- Discovered
- Apr 13, 2021
- Materiality determined
- —
- Notification sent
- May 1, 2021
- Affected individuals
- 299
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENTPHI
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified the United States Health and Human Services, Office of Civil RightsNotified the California Office of Information SecurityNotified the California Office of Health Information IntegrityNotified the California Highway PatrolNotified the California Department of Public HealthNotified the California Attorney General’s Office
- Initial access
- insider_action
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 18d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 13, 2021→ Notified: May 1, 202118d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.