California Department of State Hospitals
ent_668f2bda3d925fb3c96c2cef
Disclosures
6
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
5,014
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Department of State Hospitals
- Normalized
- california department of state hospitals— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- 🐻California State AGas victim2024-02-28
Department of State Hospitals – Atascadero reported a data breach discovered on February 15, 2024. Leave and Activity Balance reports containing full Social Security Numbers and names were disseminated to staff for timesheet approval. The incident is classified as an error/misdelivery. The agency is investigating, has notified regulators, and is offering one year of identity monitoring to affected individuals.
- 🐻California State AGas victim2021-05-11
The California Department of State Hospitals (DSH) discovered on April 13, 2021, that an employee improperly accessed personal and health information of approximately 299 individuals, including employees, former employees, and job applicants. The compromised data included names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, driver's license numbers, immigration information, and health information related to employment. DSH placed the employee on administrative leave, is cooperating with law enforcement, and has notified relevant regulatory bodies including HHS OCR and the California Attorney General. The investigation is ongoing.
- 🐻California State AGas victim2021-04-05
The CA Department of State Hospitals (DSH) disclosed that an employee improperly accessed personal and health information of approximately 2,952 employees, former employees, and job applicants. The data included names, addresses, phone numbers, email addresses, social security numbers, dates of birth, and health-related test results. The incident was discovered on March 15, 2021, during an investigation into the employee, who had previously been found to have improperly accessed patient and employee data in February 2021. The employee was placed on administrative leave, and the investigation is ongoing. No evidence of misuse of the compromised information has been found.
- 🐻California State AGas victim2021-03-17
CA Department of State Hospitals (DSH) disclosed a breach at DSH-Atascadero involving an IT employee who improperly accessed patient and employee records. The incident, discovered on Feb 25, 2021, compromised PHI including names and COVID-19 test results for approximately 1,415 patients and 617 employees (total 2,032). The employee was placed on administrative leave. No SSN or financial data was involved. DSH notified HHS OCR, CA state agencies, and law enforcement.
- CALIFORNIAHHS OCRas victim2021-03-17
California Department of State Hospitals reported to HHS on 2021-03-17 a Unauthorized Access/Disclosure affecting 5014 individuals. Breached information located on Network Server. An employee impermissibly accessed ePHI including names, addresses, diagnoses, and lab results. The entity sanctioned the employee and strengthened policies.
- 🐻California State AGas victim2013-05-24
The California Department of State Hospitals (DSH) disclosed that an employee roster containing confidential personal information, including Social Security numbers, names, position numbers, titles, and Bargaining Units, was mistakenly placed on the Patton State Hospital intranet website. The data was accessible for approximately 6 hours on May 8, 2013, before the error was discovered and corrected. DSH reviewed access logs and interviewed employees, concluding that only a small number of unauthorized employees viewed the data and further disclosure is unlikely. The incident involved employee data only.