California Correctional Health Care Services
ent_21551bad4b8c0d011f3e1aba
Disclosures
18
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
400,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Correctional Health Care Services
- Normalized
- california correctional health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (18)newest first
- CALIFORNIAHHS OCRas victim2025-04-09
California Correctional Health Care Services reported to HHS on 2025-04-09 a Unauthorized Access/Disclosure affecting 4105 individuals. Breached information located on Email. A workforce member sent an unencrypted email containing PHI (names, diagnoses, medications) to wrong recipients. CE retrained workforce members.
- California State AGas victim2025-04-09
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on August 21, 2023. The filing indicates that protected health information (PHI) and personally identifiable information (PII) were potentially compromised. Specific details regarding the attack vector, number of affected individuals, and response actions are not provided in the public summary page, as the detailed notice is contained in a redacted PDF attachment.
- California State AGas victim2024-12-23
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on November 5, 2024. The attached notice letter is redacted, preventing extraction of specific details regarding data types, affected counts, or attack vectors.
- CALIFORNIAHHS OCRas victim2024-03-14
California Correctional Health Care Services reported to HHS on 2024-03-14 an Unauthorized Access/Disclosure affecting 1,348 individuals. A workforce member inadvertently sent an email containing PHI — including names, diagnoses, lab results, and other treatment information — to an unintended recipient. The CE notified HHS, affected individuals, and the media, and responded by implementing additional administrative, technical, and security safeguards and retraining the responsible workforce member. Breached information was located in Email.
- California State AGas victim2024-03-13
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on February 26, 2024. The filing indicates that patient information was affected, implying exposure of Protected Health Information (PHI) and basic identity data. No specific attack vector, number of affected individuals, or discovery date was provided in the public summary or the redacted attachment.
- California State AGas victim2022-11-18
California Correctional Health Care Services (CCHCS) disclosed an incident where employee personal information, including full names and truncated Social Security Numbers (last four digits), was improperly posted on an internal nursing shared drive and a bulletin board at the California Health Care Facility between October 12 and October 24, 2022. The data was used for a Psychiatric Inpatient Program Seniority Listing. Upon discovery on October 24, 2022, CCHCS removed the lists, replaced them with non-PII identifiers, and mandated privacy training for involved staff. The incident is classified as an error involving employee data.
- California State AGas victim2022-07-08
On May 26, 2022, an email containing personal information of more than 500 CCHCS employees was disclosed to five unauthorized CCHCS CHCF employees. The data included names, COVID-19 testing results, vaccine status, booster dates, and religious accommodation status. CCHCS recalled the email, purged it from recipient accounts, and mandated security training for responsible staff.
- California State AGas victim2021-12-02
On September 3, 2021, California Correctional Health Care Services (CCHCS) inadvertently sent an email containing employee personal information—including names, classification, classification codes, collective bargaining unit codes, and home addresses—to labor organizations that did not have a need to know, in addition to the intended bargaining unit. The incident was an accidental misdelivery under AB119 reporting requirements.
- California State AGas victim2017-02-09
On January 23, 2017, a staff member at California Correctional Health Care Services (CCHCS) inadvertently sent an email containing inmate personal information (name, CDCR number, housing info, mental health info, provider names) to a staff member at another California State department. CCHCS was informed on January 26, 2017. The recipient confirmed deletion of the email. CCHCS provided information security training to staff.
- CALIFORNIAHHS OCRas victim2017-02-09
California Correctional Health Care Services reported to HHS on 2017-02-09 an Unauthorized Access/Disclosure affecting 738 individuals. A workforce member sent an email and spreadsheet attachment to a wrong recipient (an executive liaison at the CA Governor's Office of Emergency Services with the same last name as the intended recipient). ePHI included names, CDCR ID numbers, housing information, mental health information, and health care provider information. The CE retrained the employee and implemented email encryption. Breached info located in Email.
- California State AGas reporting2016-07-06
CDCR - California Health Care Facility reported a data breach to the California Attorney General. The breach occurred on May 2, 2016. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- California State AGas victim2016-05-15
California Correctional Health Care Services (CCHCS) notified individuals of a data breach involving the theft of an unencrypted laptop from a workforce member's vehicle on February 25, 2016. The laptop was password-protected. The incident potentially exposed confidential medical, mental health, and custodial information for individuals whose care occurred between 1996 and 2014. CCHCS identified the breach on April 25, 2016, and implemented additional security training and device protections.
- CALIFORNIAHHS OCRas victim2016-05-15
California Correctional Health Care Services reported to HHS OCR on 2016-05-15 a Theft affecting 400,000 individuals. A password-protected but unencrypted laptop was stolen from a workforce member's car. Breached ePHI included confidential medical, mental health, and custodial information. The CE notified affected parties, media, and OCR. Remediation included encryption of laptops, revised policies, workforce retraining, and sanctioning of the responsible workforce member.
- CALIFORNIAHHS OCRas victim2013-08-16
California Correctional Health Care Services reported to HHS on 2013-08-16 a Other breach affecting 1033 individuals. Breached information located on Paper/Films.
- California State AGas victim2013-07-30
California Correctional Health Care Services reported the loss of dental records containing patient names, CDCR numbers, dates of birth, and treatment plans. The records were reported missing from a staff member's possession on June 19, 2013, while off-premises. The organization conducted an investigation and provided security training to staff.
- CALIFORNIAHHS OCRas victim2013-07-30
California Correctional Health Care Services reported to HHS OCR on 2013-07-30 a breach of unknown type affecting 1,001 individuals. The breached information was located on an unspecified 'Other' medium. No business associate was involved. The entity is a state correctional healthcare provider in California; no further detail is available from the HHS portal entry.
- California State AGas victim2012-09-13
On June 20, 2012, a staff member at California Correctional Health Care Services (CCHCS) inadvertently emailed Social Security Numbers along with leave balance information to other staff members within California Department of Corrections and Rehabilitation institutions. CCHCS issued a recall request for the email but could not determine if recipients read it. Notices were sent on July 10, 2012. CCHCS stated it has taken steps to mitigate recurrence.
- California State AGas victim2012-08-07
California Correctional Health Care Services (CCHCS) reported a physical theft of mail from a kiosk mailbox at its Fresno Regional Administration building on June 11, 2012. The stolen mail contained prospective employment candidate applications with personally identifiable information, including names, social security numbers, driver's license numbers, addresses, dates of birth, and employment/education history. CCHCS reported the incident to law enforcement and redirected mail to a new location.