Regional Center of Orange County document-disposal data incident

Documents intended for secure destruction at RCOC's Cypress office were mistakenly discarded in regular trash and could not be recovered. Unrecovered documents may have contained contact, identifying, and personal health information for people served through RCOC's Cypress office.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Documents intended for secure destruction at RCOC’s Cypress office were mistakenly discarded in regular trash and could not be recovered. [1][2]

Impact

Unrecovered documents may have contained contact, identifying, and personal health information for people served through RCOC’s Cypress office. [2]

Documented data types include:

  • Dates of birth — Dates of birth; potentially present in unrecovered documents. [2]
  • Clinical information — Personal health information; potentially present in unrecovered documents. [2]
  • Names — Names; potentially present in unrecovered documents. [2]
  • Usernames and account identifiers — Unique Client Identifier numbers; potentially present in unrecovered documents. [2]
  • Contact information — Addresses, phone numbers, and email addresses; potentially present in unrecovered documents. [2]

RCOC said it was not aware of misuse of the affected information. [2]

Timeline

  1. Activity began

    Date documents intended for secure destruction were mistakenly placed in regular trash.

    [2]
  2. Discovery

    RCOC staff discovered the disposal error the following morning.

    [2]
  3. Public disclosure

    Date printed on RCOC’s consumer notice and California regulator record.

    [2]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

RCOC could not readily determine which documents or individuals were involved and notified all individuals served through its Cypress office who might have been affected. A contracted janitorial service mistakenly put documents from bins designated for secure destruction into regular trash; collection had already occurred when RCOC tried to recover them. RCOC replaced the bins with secure destruction containers and said it was strengthening procedures, staff training, and vendor oversight. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]