Confirmed breach. Intrusion May 7, 2012, discovered May 8, 2012 — the first regulatory filing landed 6 days later. 3,900 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksHIPAA✓ HHS notifiedCalifornia✓ CA 60-day OK · 6dFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
3,900
Data types
2
Health (basic) · Identity (basic)
Jurisdictions
1
CA
Linked filings
2
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
May 7, 2012
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
May 8, 2012
Reported by CALIFORNIA AG filing
🐻CALIFORNIAHHS OCRFirst filinglinked via operator-confirmed · 100%
St. Mary Medical Center (CA) reported to HHS OCR on 2012-05-14 a Loss affecting 3,900 individuals. Breached information was located on an Other Portable Electronic Device. No business associate was identified as present. No further description was provided by the covered entity.
Affected (this filing): 3,900
HHS notified
🐻California State AGMost recentlinked via operator-confirmed · 100%
St Mary Medical Center reported the loss of an unencrypted thumb drive containing patient medical information, including names, account numbers, diagnoses, admission/discharge dates, physician names, and medical record numbers. The incident was discovered on May 8, 2012. The drive did not contain SSNs, driver's license numbers, or home addresses. The hospital is reviewing security policies and increasing IT security education.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.