The California Department of Public Health reported a data breach involving the Women, Infants, and Children (WIC) Program on September 26, 2013. The breach occurred on August 20, 2013, when a Madera County WIC employee mistakenly disclosed personal and medical information, including names and expected delivery dates, to another participant. The number of individuals affected is unknown.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-42780
TPRM report: https://www.rankiteo.com/company/california-department-of-public-health
"id": "cal104080425",
"linkid": "california-department-of-public-health",
"type": "Breach",
"date": "8/2013",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'California, USA',
'name': 'California Department of Public Health',
'type': 'Government Agency'}],
'attack_vector': 'Human Error',
'data_breach': {'personally_identifiable_information': ['Names',
'Expected Delivery '
'Dates'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Medical Information']},
'date_detected': '2013-08-20',
'date_publicly_disclosed': '2013-09-26',
'description': 'The California Department of Public Health reported a data '
'breach involving the Women, Infants, and Children (WIC) '
'Program on September 26, 2013. The breach occurred on August '
'20, 2013, when a Madera County WIC employee mistakenly '
'disclosed personal and medical information, including names '
'and expected delivery dates, to another participant. The '
'number of individuals affected is unknown.',
'impact': {'data_compromised': ['Personal Information',
'Medical Information']},
'motivation': 'Accidental',
'post_incident_analysis': {'root_causes': 'Human Error'},
'references': [{'source': 'California Department of Public Health'}],
'threat_actor': 'Internal Employee',
'title': 'California Department of Public Health WIC Program Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Mistaken Disclosure'}