MisusePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, Inc.
bd_2c298c8bd0d24abf · schema v1 · pii pii-v1
Full breach record for Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, Inc. →Kaiser Permanente Northern California reported that a workforce member inappropriately accessed patient medical records without a reasonable basis. The incident was discovered on May 16, 2024. Affected data included demographic information (name, address, email, phone, DOB, medical record number) and medical information. Social Security numbers and financial information were not involved. Access was removed and an investigation was launched.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7555c4fb88780054HHS OCRfiled 2024-07-15Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-588624
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2024
- Raw hash
- a54b620a0f419b3c2685c46b1c8d7cd906ebef85621ea0a557ec14f8fd3fd0f8
Reporting entity
- Name
- Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, Inc.norm: kaiser foundation hospitals northern california and the permanente medical
- Domain
- kp.org
Victim entity
- Name
- Kaiser Foundation Hospitals, Northern California and The Permanente Medical Group, Inc.norm: kaiser foundation hospitals northern california and the permanente medical
- Domain
- kp.org
Incident
- Discovered
- May 16, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Insider
- Threat actor
- Internal
- Regulator citations
- Reporting these facts to federal and state agencies
- Initial access
- insider_action
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.