Sources and methodology

Every fact published on BreachBook traces to a citable government or court source. This page documents each source, how it is retrieved, and when its endpoint was last verified. A breach record with zero sources is never rendered.

Source registry

SourceType codeFormatRetrieval methodEndpointPhaseLast verified
HHS Office for Civil Rights breach portalhhs_ocrCSV export via JSF form postbackscheduled fetch, daily 06:00 UTCocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf1verified 2026-08-06 — retrieval confirmed against the live portal
Maine Attorney General breach notificationsmaine_agHTML list + PDF lettersscheduled fetch, dailymaine.gov/ag/consumer/identity_theft/2pending — endpoint documented 2026-08-02, not yet fetch-verified
California Attorney General breach listca_agHTML table + sample noticesscheduled fetch, dailyoag.ca.gov/privacy/databreach/list2pending — endpoint documented 2026-08-02, not yet fetch-verified
Washington Attorney General breach notificationswa_agHTML/dashboardscheduled fetch, dailyatg.wa.gov/data-breach-notifications2pending — endpoint documented 2026-08-02, not yet fetch-verified
Texas Attorney General data breach reportstx_agHTML listscheduled fetch, dailyoag.texas.gov/consumer-protection/data-breach-reporting3pending — endpoint documented 2026-08-02, not yet fetch-verified
SEC EDGAR 8-K Item 1.05 filingssec_8kfull-text search API (JSON)scheduled fetch, dailyefts.sec.gov/LATEST/search-index via sec.gov/edgar/search3pending — endpoint documented 2026-08-02, not yet fetch-verified
CourtListener REST API v4courtlistenerJSON API (token required)scheduled fetch, hourly for tracked docketscourtlistener.com/api/rest/v4/4pending — endpoint documented 2026-08-02, not yet fetch-verified
HHS OCR 42 CFR Part 2 breach reporthhs_part2CSV export via JSF form postbackscheduled fetch, daily 06:00 UTCocrportal.hhs.gov/ocr/breach/breach_report_part2.jsf1verified 2026-08-07 — retrieval confirmed against the live portal; listing held no records on that date

Endpoint verification policy: government portals rotate paths without notice. Each ingest run re-verifies its endpoint and fails loudly on a 404 — a source is never silently skipped. When an endpoint moves, this table is updated with the new URL and a fresh verification date.

Current coverage, stated precisely

Being explicit about what this record does and does not yet contain matters more than appearing complete.

Retrieval conduct

Seeded reference data

Contact and error reports

BreachBook is published by Oak and Main Developers LLC, 2108 N St., Sacramento, CA 95816. See about for the publisher of record.

Corrections and source disputes go to [email protected] — include the page URL and a citation to the government or court document that supports the correction. Reports can also be filed in the open as an issue at github.com/kevynsgrin-a11y/BreachLedger, which requires a GitHub account. (The repository keeps its original name; the site is BreachBook.) Security reports go to [email protected].

What this site deliberately does not do