Castro Valley Health, Inc. disclosed a data security incident involving the inadvertent transfer of patient information to a third-party website (Docker Hub) between 2016 and 2017. The company discovered the breach on April 21, 2020, and removed the data. Affected data included patient names, dates of birth, medical record numbers, and therapist details. No clinical notes, SSNs, or financial data were involved. The organization implemented enhanced security audits, policy updates, and employee training.