California College of Arts reported to HHS on 2018-02-26 a Theft affecting 623 individuals. Breached information located on Laptop.
Affected (this filing): 623
Clustered 2 filings across 1 jurisdiction · filed Feb 26, 2018. View entity profile → Other incidents for this victim →
incident inc_c3a7268de240494e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Identity (basic) · Government ID · Health (basic)
CA
HHS OCR · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Jan 19, 2018
When the intrusion reportedly occurred, per the linked filings
Jan 19, 2018
Reported by HHS OCR, CALIFORNIA AG filings
California College of Arts reported to HHS on 2018-02-26 a Theft affecting 623 individuals. Breached information located on Laptop.
Affected (this filing): 623
On January 19, 2018, a laptop used by an employee of California College of the Arts was stolen from the employee's vehicle. The device may have contained names, Social Security numbers, dates of birth, subscriber member numbers, and health insurance information for up to 2,581 California residents. The College changed passwords, monitored for device activity, and engaged third-party cybersecurity firms. No evidence of misuse was found. Notices were sent on February 26, 2018, offering one year of credit monitoring.
Affected (this filing): 2,581
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.