AccidentalMisconfigurationCustomer Data InvolvedPHIHEALTH_BASICLowResolved
Kaiser Permanente Health Plan, Inc of Northern California
bd_140dbb06e27d3cab · schema v1 · pii pii-v1
Full breach record for Kaiser Permanente Health Plan, Inc of Northern California →Kaiser Permanente Health Plan, Inc of Northern California disclosed a misconfiguration error on kp.org during a website upgrade on October 12, 2016. For approximately two hours, protected health information (PHI) viewed by signed-in members may have been mistakenly visible to other visitors. The error was repaired by 1:43 a.m. on October 13, 2016. No Social Security numbers or banking information were disclosed. The organization is updating testing procedures for website updates.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64764
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2016
- Raw hash
- c5a8a23a8c6a8d09998e7ba02c308be86213e12aff03cec5ae57dd01e4f54f5d
Reporting entity
- Name
- Kaiser Permanente Health Plan, Inc of Northern Californianorm: kaiser permanente health plan inc of northern california
- Domain
- kp.org
Victim entity
- Name
- Kaiser Permanente Health Plan, Inc of Northern Californianorm: kaiser permanente health plan inc of northern california
- Domain
- kp.org
Incident
- Discovered
- Oct 13, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASIC
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.