MisuseData MishandlingCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINORMediumContained
CalOptima
bd_3cb594a1301d2dfa · schema v1 · pii pii-v1
Full breach record for CalOptima →On August 17, 2016, a departing CalOptima employee downloaded protected health information, including names, demographic data, and social security numbers for some members (including minors), to an unencrypted USB flash drive. The drive was returned to CalOptima. The organization is investigating the contents and does not believe the information was shared. CalOptima is offering credit/identity monitoring services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64419
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 14, 2016
- Raw hash
- 081831958df5e248bcfb50af15f1c6d7b8646debced8ab3b84cb961340b1873f
Reporting entity
- Name
- CalOptimanorm: caloptima
- Domain
- caloptima.org
Victim entity
- Name
- CalOptimanorm: caloptima
- Domain
- caloptima.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMINOR
- Attack vector
- Insider
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.