California Department of Corrections and Rehabilitation
ent_dd661d0d347f164b841dafd2
Disclosures
10
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
236,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Department of Corrections and Rehabilitation
- Normalized
- california department of corrections and rehabilitation— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- CALIFORNIAHHS OCRas victim2022-08-22
California Department of Corrections and Rehabilitation reported to HHS on 2022-08-22 a Hacking/IT Incident affecting 236,000 individuals. Breached information located on Network Server. The incident involved a ransomware attack that encrypted and exfiltrated PHI, including names, SSNs, DOB, driver's license numbers, diagnoses, lab results, medications, and financial information. The entity secured its network, notified HHS, individuals, and media, and implemented additional safeguards.
- California State AGas victim2022-08-22
California Department of Corrections and Rehabilitation (CDCR) notified individuals of unauthorized access to a file-sharing platform. Suspicious activity was discovered in January 2022, dating back to December 2021. An investigation confirmed an unauthorized user accessed the system, but no evidence of data copying or downloading was found. Affected data included names, addresses, phone numbers, emails, dates of birth, and medical information (COVID-19 testing, mental health, substance use treatment). No SSNs or financial data were involved. CDCR shut down the platform and migrated to a new system with enhanced security.
- California State AGas victim2022-02-08
On January 5, 2022, an employee at Calipatria State Prison, operated by the California Department of Corrections and Rehabilitation, inadvertently emailed a document containing personal information to the wrong person. The exposed data included first and last name, date of birth, and Social Security number. The agency is reviewing and revising procedures to prevent recurrence.
- California State AGas victim2020-07-14
The California Department of Corrections and Rehabilitation (CDCR) experienced a data breach involving a SharePoint site used by the Office of Peace Officer Selection. On May 6, 2020, a domain group for all CDCR staff was inadvertently granted 'read only' access to the site, which contained personal identifying information including names, Social Security numbers, and addresses. The incident was discovered on May 7, 2020. The agency immediately removed the inadvertent access and initiated an audit of SharePoint permissions. Affected individuals were notified on May 12, 2020, and advised to place fraud alerts on their credit files.
- California State AGas victim2017-12-26
California Department of Corrections and Rehabilitation submitted a breach notification sample to the California Office of the Attorney General. The filing is a sample form; the attached PDF is not provided in the source text, so no specific incident details, data types, or affected counts could be extracted.
- California State AGas victim2016-11-21
The California Department of Corrections and Rehabilitation reported a breach of confidential information occurring on October 28, 2016. The filing provides only the date of the breach and the organization name; specific details regarding the nature of the incident, data types, or affected individuals are not present in the provided source text.
- California State AGas victim2015-07-13
California Department of Corrections and Rehabilitation submitted a sample breach notification to the California Office of the Attorney General. The filing is a sample submission and does not contain specific details regarding the incident, affected individuals, or response actions.
- California State AGas victim2014-04-02
California Department of Corrections and Rehabilitation reported that an employee roster containing full names and the last 6 digits of Social Security numbers was found in an unsecure desk drawer at California Correctional Institution. The roster was used for TB testing between March 3 and March 7, 2014, and discovered on March 9, 2014. The agency is reviewing procedures to prevent recurrence.
- California State AGas victim2013-08-20
The California Department of Corrections and Rehabilitation reported a data security breach to the California Attorney General. The breach occurred on July 26, 2013. The provided source document contains only the filing metadata and a link to the notice letter; the content of the letter is not available in the input, so specific details regarding data types, affected counts, and attack vectors could not be extracted.
- California State AGas reporting2012-11-01
On September 26, 2012, Salinas Valley State Prison discovered that a database file containing personal information for custody staff was accessible to all staff due to a misconfiguration. The data included names, Social Security numbers, phone numbers, addresses, and position information. The file was secured and relocated to a restricted server location. The organization is reviewing procedures to prevent recurrence.