Confirmed breach. Intrusion Oct 9, 2015, discovered Oct 9, 2015 — the first regulatory filing landed 53 days later. 35,404 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
35,404
Data types
1
PHI
Jurisdictions
1
CA
Linked filings
2
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Oct 9, 2015
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Oct 9, 2015
Reported by CALIFORNIA AG filing
53 days
🐻CALIFORNIAHHS OCRFirst filinglinked via same-victim cross-source · 100%
HHS OCR 'Wall of Shame' entry: Keenan & Associates (CA), a Business Associate, reported an Unauthorized Access/Disclosure breach affecting 35,404 individuals, with PHI located on a Network Server. Submitted to OCR on 2015-12-01. The OCR row contains no narrative on attack vector, threat actor, root cause, or remediation.
Affected (this filing): 35,404
🐻California State AGMost recentlinked via same-victim cross-source · 100%
Keenan & Associates, a third-party health insurance administrator, discovered on October 9, 2015, that documents containing employee and dependent information (names, addresses, phone numbers, birth dates, plan identifiers, and some SSNs) were potentially searchable on the Internet due to a vendor's misconfiguration of security settings on a portal. The documents did not contain medical claims or diagnostic codes. Keenan reconfigured the portal, engaged Kroll for two years of identity monitoring, and instructed vendors to stop using the responsible software tool.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.