Central Valley Regional Center
ent_e16e076029ae9da7ba5ab1cd
Disclosures
4
State AG · HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
15,975
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Central Valley Regional Center
- Normalized
- central valley regional center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🐻California State AGas victim2025-09-11
Central Valley Regional Center, Inc. disclosed that a third-party janitorial service improperly disposed of confidential documents containing private health and financial information (including SSNs) between March and July 2025. The incident was discovered in July 2025. The organization contained the incident, notified authorities, and implemented physical security controls for shredding bins and revised vendor procedures.
- 🐻California State AGas victim2019-10-24
Central Valley Regional Center (CVRC) reported a data security incident in California where an unauthorized third party accessed an employee's email account between July 25 and August 2, 2019. The breach exposed personal information of 11,990 California residents, including names, SSNs, driver's license numbers, Medi-Cal numbers, and financial account data. CVRC disabled access, engaged forensic investigators, notified the FBI, and provided 12 months of complimentary credit monitoring to affected individuals.
- 🦬Montana State AGas victim2019-10-18
Central Valley Regional Center reported a data breach to the Montana Attorney General. The breach was reported on 2019-10-18. The breach occurred from 7/25/2019 to 8/2/2019. 1 Montana residents were affected.
- CALIFORNIAHHS OCRas victim2019-10-11
Central Valley Regional Center reported to HHS on 2019-10-11 a Hacking/IT Incident affecting 15975 individuals. Breached information located on Email. The cyber-attack compromised electronic protected health information (ePHI) including names, addresses, birthdates, SSNs, and driver's license information. The CE notified HHS, affected individuals, and the media, and implemented new technical safeguards and workforce retraining following OCR's investigation.