Confirmed breach. Intrusion Aug 1, 2014–Sep 17, 2014, discovered Sep 17, 2014 — the first regulatory filing landed 58 days later. 30,000 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksCalifornia✓ CA 60-day OK · 56dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
30,000
Data types
3
Health (basic) · Identity (basic) · Government ID
Jurisdictions
1
CA
Linked filings
2
HHS OCR · State AG
Sensitive data
identity_government
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Aug 1, 2014 → Sep 17, 2014
When the intrusion reportedly occurred, per the linked filings
47 days
Breach discovered
Sep 17, 2014
Reported by CALIFORNIA AG filing
58 days
🐻California State AGFirst filinglinked via operator-confirmed · 100%
REEVE-WOODS EYE CENTER notified patients of a security breach discovered on September 17, 2014. Unknown individuals breached the clinic's server and installed malware to capture screenshots containing PHI, SSNs, and insurance IDs. The malware was likely installed in August 2014. No evidence of actual misuse was found at the time of notification. Investigation was ongoing.
CA 60-day OK · 56d
🐻CALIFORNIAHHS OCRMost recentlinked via operator-confirmed · 100%
Reeve-Woods Eye Center (CA) reported to HHS OCR on 2014-11-15 a malware incident affecting 30,000 individuals (the web description references 43,000). Malware infiltrated the CE's electronic network approximately August 1 – September 17, 2014, causing screenshots and keystrokes to be exfiltrated outside the network. ePHI exposed included names, SSNs, dates of birth, addresses, phone numbers, dates of service, insurance information, diagnosis codes, treatment information, and medical histories. The CE cooperated with the FBI, cleared the malware, and strengthened technical security controls. Breached information located on Network Server.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.