CALIFORNIASocial EngineeringHealthcareFinancial ServicesHealthcarePretextingStolen CredentialsCustomer Data InvolvedHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
California Physicians' Services
bd_3506698715777776 · schema v1 · pii pii-v1
Full breach record for California Physicians' Services →On December 7, 2015, Blue Shield of California discovered that its network servers were breached via social engineering at its call centers in Costa Rica. The breach, submitted to HHS on January 14, 2016, affected 20,764 individuals. PHI exposed included names, addresses, dates of birth, and Social Security numbers. Remediation included disabling compromised credentials, redistributing new passwords, two-factor authentication for VPN access, and social engineering training for call center staff. OCR obtained assurances of corrective action.
HIPAA clock✓ HHS notified5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b8cea60edf2908b2California State AGfiled 2016-01-14Verified by operator
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 14, 2016
- Raw hash
- eb184adbc927718e0255b436e44f6e865e54be8c97cb515b63f4db1f752ce37b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
- Industry
- Insurance — Health
Victim entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Dec 7, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 20,764
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566 Phishing
- Threat actor
- External
- Regulator citations
- HHS OCR breach notification filed; OCR obtained assurances regarding corrective actions
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Dec 7, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.