HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
KAISER PERMANENTE GROUP TRUST
bd_2653d77d0ec34991 · schema v1 · pii pii-v1
Full breach record for KAISER PERMANENTE GROUP TRUST →Kaiser Permanente notified members that a provider's email account containing protected health information was compromised by an unknown individual for approximately 13 hours on August 12, 2019. The incident was discovered on August 19, 2019. Affected data included names, medical record numbers, dates of service, diagnoses, and treatment details. Social Security numbers and financial information were not involved. Kaiser changed the account password and strengthened email security controls.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5459bafd80c60a17HHS OCRfiled 2019-09-26Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150863
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2019
- Raw hash
- dca6a1909b0cfe829adc6ff2adfe82e66c880a934329f8f6c2c7a2306f025276
Reporting entity
- Name
- KAISER PERMANENTE GROUP TRUSTnorm: kaiser permanente
- Domain
- kaiserpermanente.org
Victim entity
- Name
- KAISER PERMANENTE GROUP TRUSTnorm: kaiser permanente
- Domain
- kaiserpermanente.org
Incident
- Discovered
- Aug 19, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.