California Department of Corrections and Rehabilitation
ent_dd661d0d347f164b841dafd2
Disclosures
11
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
236,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Department of Corrections and Rehabilitation
- Normalized
- california department of corrections and rehabilitation— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- CALIFORNIAHHS OCRas victim2022-08-22
California Department of Corrections and Rehabilitation reported to HHS on 2022-08-22 a Hacking/IT Incident affecting 236,000 individuals. Breached information located on Network Server. The incident involved a ransomware attack that encrypted and exfiltrated PHI, including names, SSNs, DOB, driver's license numbers, diagnoses, lab results, medications, and financial information. The entity secured its network, notified HHS, individuals, and media, and implemented additional safeguards.
- 🐻California State AGas victim2022-08-22
California Department of Corrections and Rehabilitation (CDCR) disclosed a data breach involving a password-protected file-sharing platform. Suspicious activity was discovered in January 2022, dating back to December 2021. An unauthorized user accessed the system, but no data was copied or downloaded. Affected data included names, addresses, contact info, and PHI (mental health, substance use treatment, COVID-19 results). CDCR shut down the platform and launched a multi-agency investigation.
- 🐻California State AGas victim2022-02-08
On January 5, 2022, an employee at Calipatria State Prison, operated by the California Department of Corrections and Rehabilitation, inadvertently emailed a document containing personal information to the wrong person. The exposed data included first and last name, date of birth, and Social Security number. The agency is reviewing and revising procedures to prevent recurrence.
- 🐻California State AGas victim2020-07-14
California Department of Corrections and Rehabilitation (CDCR) notified individuals of a data breach discovered May 7, 2020. A domain group for CDC staff was inadvertently granted read-only access to a SharePoint site containing names, SSNs, and addresses. CDCR removed access immediately and is auditing permissions.
- 🐻California State AGas victim2017-12-26
California Department of Corrections and Rehabilitation submitted a breach notification sample to the California Office of the Attorney General. The filing is a sample form; the attached PDF is not provided in the source text, so no specific incident details, data types, or affected counts could be extracted.
- 🐻California State AGas victim2016-11-21
The California Department of Corrections and Rehabilitation reported a breach of confidential information occurring on October 28, 2016. The filing provides only the date of the breach and the organization name; specific details regarding the nature of the incident, data types, or affected individuals are not present in the provided source text.
- 🐻California State AGas reporting2016-07-06
CDCR - California Health Care Facility reported a data breach to the California Attorney General. The breach occurred on May 2, 2016. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- 🐻California State AGas victim2015-07-13
California Department of Corrections and Rehabilitation submitted a sample breach notification to the California Office of the Attorney General. The filing is a sample submission and does not contain specific details regarding the incident, affected individuals, or response actions.
- 🐻California State AGas victim2014-04-02
California Correctional Institution (operated by CDCR) disclosed a security incident on April 1, 2014, involving an employee roster containing names and partial SSNs (last 6 digits) found in an unsecure desk drawer at the Tehachapi facility. The incident occurred between March 3 and March 7, 2014. The agency notified affected individuals and recommended fraud alerts.
- 🐻California State AGas victim2013-08-20
The California Department of Corrections and Rehabilitation reported a data security breach to the California Attorney General. The breach occurred on July 26, 2013. The provided source document contains only the filing metadata and a link to the notice letter; the content of the letter is not available in the input, so specific details regarding data types, affected counts, and attack vectors could not be extracted.
- 🐻California State AGas reporting2012-11-01
On September 26, 2012, Salinas Valley State Prison discovered that a database file containing personal information for custody staff was accessible to all staff due to a misconfiguration. The data included names, Social Security numbers, phone numbers, addresses, and position information. The file was secured and relocated to a restricted server location. The organization is reviewing procedures to prevent recurrence.