California Correctional Health Care Services
ent_21551bad4b8c0d011f3e1aba
Disclosures
16
State AG · HHS OCR · 2 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
400,000
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Correctional Health Care Services
- Normalized
- california correctional health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (16)newest first
- 🐻California State AGas victim2025-04-09
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on August 21, 2023. The filing indicates that protected health information (PHI) and personally identifiable information (PII) were potentially compromised. Specific details regarding the attack vector, number of affected individuals, and response actions are not provided in the public summary page, as the detailed notice is contained in a redacted PDF attachment.
- 🐻California State AGas victim2024-12-23
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on November 5, 2024. The attached notice letter is redacted, preventing extraction of specific details regarding data types, affected counts, or attack vectors.
- CALIFORNIAHHS OCRas victim2024-03-14
California Correctional Health Care Services reported to HHS on 2024-03-14 an Unauthorized Access/Disclosure affecting 1,348 individuals. A workforce member inadvertently sent an email containing PHI — including names, diagnoses, lab results, and other treatment information — to an unintended recipient. The CE notified HHS, affected individuals, and the media, and responded by implementing additional administrative, technical, and security safeguards and retraining the responsible workforce member. Breached information was located in Email.
- 🐻California State AGas victim2024-03-13
California Correctional Health Care Services reported a data breach to the California Attorney General. The incident occurred on February 26, 2024. The filing indicates that patient information was affected, implying exposure of Protected Health Information (PHI) and basic identity data. No specific attack vector, number of affected individuals, or discovery date was provided in the public summary or the redacted attachment.
- 🐻California State AGas victim2022-11-18
California Correctional Health Care Services (CCHCS) disclosed a data breach involving the unauthorized internal posting of employee seniority lists containing truncated Social Security Numbers (SSNs) and full names. The incident occurred between October 12 and October 24, 2022, when lists were posted on an internal nursing shared drive and a physical bulletin board at the California Health Care Facility. CCHCS discovered the error on October 24, 2022, and immediately removed the lists, replaced them with non-PII identifiers, and mandated privacy training for involved staff. No evidence of misuse was found.
- 🐻California State AGas victim2022-07-08
On May 26, 2022, an email containing personal information of more than 500 CCHCS employees was disclosed to five unauthorized CCHCS CHCF employees. The data included names, COVID-19 testing results, vaccine status, booster dates, and religious accommodation status. CCHCS recalled the email, purged it from recipient accounts, and mandated security training for responsible staff.
- 🐻California State AGas victim2021-12-02
On September 3, 2021, California Correctional Health Care Services (CCHCS) inadvertently sent an email containing employee personal information—including names, classification, classification codes, collective bargaining unit codes, and home addresses—to labor organizations that did not have a need to know, in addition to the intended bargaining unit. The incident was an accidental misdelivery under AB119 reporting requirements.
- 🐻California State AGas victim2017-02-09
On January 23, 2017, a staff member at California Correctional Health Care Services (CCHCS) inadvertently sent an email containing inmate personal information (name, CDCR number, housing info, mental health info, provider names) to a staff member at another California State department. CCHCS was informed on January 26, 2017. The recipient confirmed deletion of the email. CCHCS provided information security training to staff.
- CALIFORNIAHHS OCRas victim2017-02-09
California Correctional Health Care Services reported to HHS on 2017-02-09 an Unauthorized Access/Disclosure affecting 738 individuals. A workforce member sent an email and spreadsheet attachment to a wrong recipient (an executive liaison at the CA Governor's Office of Emergency Services with the same last name as the intended recipient). ePHI included names, CDCR ID numbers, housing information, mental health information, and health care provider information. The CE retrained the employee and implemented email encryption. Breached info located in Email.
- 🐻California State AGas victim2016-07-06
CDCR - California Health Care Facility reported a data breach to the California Attorney General. The breach occurred on May 2, 2016. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- 🐻California State AGas victim2016-05-15
California Correctional Health Care Services (CCHCS) reported the theft of an unencrypted, password-protected laptop from an employee's vehicle on February 25, 2016. The incident was identified on April 25, 2016. The laptop may have contained confidential medical, mental health, and custodial information related to individuals' custody and care between 1996 and 2014. CCHCS provided security training and reinforced practices.
- CALIFORNIAHHS OCRas victim2016-05-15
California Correctional Health Care Services reported to HHS OCR on 2016-05-15 a Theft affecting 400,000 individuals. A password-protected but unencrypted laptop was stolen from a workforce member's car. Breached ePHI included confidential medical, mental health, and custodial information. The CE notified affected parties, media, and OCR. Remediation included encryption of laptops, revised policies, workforce retraining, and sanctioning of the responsible workforce member.
- FEDERALHHS OCRas victim2013-08-16
California Correctional Health Care Services reported to HHS on 2013-08-16 a Other breach affecting 1033 individuals. Breached information located on Paper/Films.
- 🐻California State AGas victim2013-07-30
California Correctional Health Care Services reported the loss of dental records containing patient names, CDCR numbers, dates of birth, and treatment plans. The records were reported missing from a staff member's possession on June 19, 2013, while off-premises. The organization conducted an investigation and provided security training to staff.
- 🐻California State AGas victim2012-09-13
On June 20, 2012, a staff member at California Correctional Health Care Services (CCHCS) inadvertently emailed Social Security Numbers along with leave balance information to other staff members within California Department of Corrections and Rehabilitation institutions. CCHCS issued a recall request for the email but could not determine if recipients read it. Notices were sent on July 10, 2012. CCHCS stated it has taken steps to mitigate recurrence.
- 🐻California State AGas victim2012-08-07
California Correctional Health Care Services (CCHCS) reported a physical theft of mail from a kiosk mailbox at its Fresno Regional Administration building on June 11, 2012. The stolen mail contained prospective employment candidate applications with personally identifiable information, including names, social security numbers, driver's license numbers, addresses, dates of birth, and employment/education history. CCHCS reported the incident to law enforcement and redirected mail to a new location.