Sources and methodology
Every fact published on BreachBook traces to a citable government or court source. This page documents each source, how it is retrieved, and when its endpoint was last verified. A breach record with zero sources is never rendered.
Source registry
| Source | Type code | Format | Retrieval method | Endpoint | Phase | Last verified |
|---|---|---|---|---|---|---|
| HHS Office for Civil Rights breach portal | hhs_ocr | CSV export | scheduled fetch, daily | ocrportal.hhs.gov/ocr/breach/breach_report.jsf | 1 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| Maine Attorney General breach notifications | maine_ag | HTML list + PDF letters | scheduled fetch, daily | maine.gov/ag/consumer/identity_theft/ | 2 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| California Attorney General breach list | ca_ag | HTML table + sample notices | scheduled fetch, daily | oag.ca.gov/privacy/databreach/list | 2 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| Washington Attorney General breach notifications | wa_ag | HTML/dashboard | scheduled fetch, daily | atg.wa.gov/data-breach-notifications | 2 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| Texas Attorney General data breach reports | tx_ag | HTML list | scheduled fetch, daily | oag.texas.gov/consumer-protection/data-breach-reporting | 3 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| SEC EDGAR 8-K Item 1.05 filings | sec_8k | full-text search API (JSON) | scheduled fetch, daily | efts.sec.gov/LATEST/search-index via sec.gov/edgar/search | 3 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
| CourtListener REST API v4 | courtlistener | JSON API (token required) | scheduled fetch, hourly for tracked dockets | courtlistener.com/api/rest/v4/ | 4 | pending — endpoint documented 2026-08-02, not yet fetch-verified |
Endpoint verification policy: government portals rotate paths without notice. Each ingest run re-verifies its endpoint and fails loudly on a 404 — a source is never silently skipped. When an endpoint moves, this table is updated with the new URL and a fresh verification date.
Retrieval conduct
- Every request identifies this project with a descriptive User-Agent including a contact URL (required by SEC EDGAR access policy; extended to all sources as baseline conduct).
- Requests are rate-limited to at most 1 request/second per host, and robots.txt is respected.
- Raw payloads are stored with a SHA-256 checksum; unchanged payloads are not reprocessed.
- From Phase 4, source notification PDFs are archived to durable storage so the record survives if an agency rotates or removes its URLs.
Seeded reference data
- Data class weights are editorial policy, published in full at /severity, versioned in
packages/severity/rubric.json. - State notification-law reference (
state_rightstable): seeded 2026-08-02 from statutory research with an independent cross-check pass; each row carries alast_verifieddate. Rows are re-verified against the official state legislature source before the corresponding/rights/[state]page ships in Phase 3, and any figure that could not be confirmed is stored as null rather than guessed. Statute URLs point to official state legislature sites or the state's contracted official code publisher. Where a state offers no stable per-section link (for example Mississippi, whose official code is a Lexis-hosted service), the URL is the official legislature gateway and the row's research notes say how to navigate to the section. - Remediation modules: every module cites one authoritative federal source — consumer.ftc.gov, IdentityTheft.gov, IRS.gov, consumerfinance.gov (CFPB), or USA.gov — as the authority for its instructions, with a
last_verifieddate.
Contact and error reports
Corrections and source disputes are tracked in the project repository at github.com/kevynsgrin-a11y/BreachLedger — open an issue with a citation to the government or court document that supports the correction. (The repository keeps its original name; the site is BreachBook.) This page is the canonical place to find the current correction channel, and a dedicated corrections address will be published here when one is in service.
What this site deliberately does not do
- No email-lookup or "was I breached" search. That function exists at Have I Been Pwned, which we link to and never proxy or replicate.
- No legal advice, no claim processing. Settlement pages link only to the official settlement administrator.