AccidentalMisconfigurationData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowResolved
Kaiser Foundation Hospitals
bd_0c98f04ac29362cd · schema v1 · pii pii-v1
Full breach record for Kaiser Foundation Hospitals →Kaiser Foundation Hospitals disclosed a data breach involving its online Estimates tool (kp.org) between November 16 and 28, 2016. A system error allowed subsequent users of the tool to view previous users' protected health information, including names, ages, addresses, and financial copay/deductible details. No SSNs or banking information were compromised. The error was discovered on November 28, 2016, and corrected by rolling back the update. The incident is classified as an error/misconfiguration.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65536
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 20, 2016
- Raw hash
- b115b3e1df431c763497e3ea4f198c102629ff7f54fad586ea6127131753d6ac
Reporting entity
- Name
- Kaiser Foundation Hospitalsnorm: kaiser foundation hospitals
- Domain
- healthy.kaiserpermanente.org
Victim entity
- Name
- Kaiser Foundation Hospitalsnorm: kaiser foundation hospitals
- Domain
- healthy.kaiserpermanente.org
Incident
- Discovered
- Nov 28, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1535 Unauthorized Access to Cloud Compute Instances
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.