Confirmed breach. Intrusion Sep 26, 2020–Oct 12, 2020, discovered Oct 12, 2020 — the first regulatory filing landed 218 days later (flagged late). 420,433 individuals reported across the linked filings.
Health Plan of San Joaquin (HPSJ) experienced a hacking incident from September 26 to October 12, 2020, discovered on October 23, 2020. The breach affected 420,433 individuals, compromising names and Social Security numbers. HPSJ notified consumers on May 18, 2021, and offered 12 months of identity theft protection services through Equifax.
Affected (this filing): 420,433
ME AG >90d · 207d
🐻California State AGMost recentlinked via multistate filing link · 100%
Health Plan of San Joaquin (HPSJ) notified California residents of a data breach involving unauthorized access to employee email accounts. The incident occurred between September 26, 2020, and October 12, 2020, following a phishing attack. Affected data included names, SSNs, DOBs, and health information. HPSJ reset passwords, engaged forensic specialists, and offered 12 months of free identity monitoring via Equifax.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.