HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Kaiser Foundation Hospitals
bd_32c7eed1cbbbeb93 · schema v1 · pii pii-v1
Full breach record for Kaiser Foundation Hospitals →Kaiser Permanente discovered on September 3, 2024, that an unauthorized party accessed the email accounts of two workforce members. The incident occurred between August and September 2024. Affected data included protected health information (PHI) such as names, dates of birth, medical record numbers, and medical information. Social Security numbers and credit card numbers were not involved. Kaiser terminated access and reset passwords.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_a1be27e2d6715722HHS OCRfiled 2024-11-01Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-594220
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 1, 2024
- Raw hash
- c0cc6c038aa15228f03c7e0222f9819fc21ad3a2abf7c69472e77eecbdbe4c45
Reporting entity
- Name
- Kaiser Foundation Hospitalsnorm: kaiser foundation hospitals
- Domain
- healthy.kaiserpermanente.org
Victim entity
- Name
- Kaiser Foundation Hospitalsnorm: kaiser foundation hospitals
- Domain
- healthy.kaiserpermanente.org
Incident
- Discovered
- Sep 3, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.