Confirmed breach. Intrusion Oct 12, 2016–Aug 12, 2021, discovered Aug 12, 2021 — the first regulatory filing landed 22 days later. 1,738 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksHIPAA✓ HHS notifiedCalifornia✓ CA 60-day OK · 1dFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedmoderate sensitivity
Affected (total reported)
1,738
Data types
3
PHI · Health (basic) · Identity (basic)
Jurisdictions
1
CA
Linked filings
2
HHS OCR · State AG
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Oct 12, 2016 → Aug 12, 2021
When the intrusion reportedly occurred, per the linked filings
1,765 days
Breach discovered
Aug 12, 2021
Reported by CALIFORNIA AG filing
🐻CALIFORNIAHHS OCRFirst filinglinked via same-victim cross-source · 100%
California Department of State Hospitals - Coalinga reported to HHS on 2021-09-03 a Unauthorized Access/Disclosure affecting 1738 individuals. Breached information located on Email. A workforce member impermissibly disclosed PHI including names, DOBs, and treatment info. CE notified HHS, individuals, and media, and amended policies.
Department of State Hospitals - Coalinga disclosed a data breach involving the unauthorized disclosure of patient rosters to the U.S. District Court, Eastern District of California. The incident, discovered around August 12, 2021, involved the provision of patient names, case numbers, birth dates, and commitment details to the Court Clerk for filing fee waiver eligibility determinations. No SSNs or financial data were included. DSH-C notified affected individuals, engaged forensic and legal counsel, and reported the breach to multiple state and federal regulators including HHS OCR and the California DOJ. Remediation includes reviewing and revising patient record procedures.
CA 60-day OK · 1d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.