CalOptima
bd_43ee7915429a163e · schema v1 · pii pii-v1
Full breach record for CalOptima →3 incidents on fileCalOptima (CA Health Plan) reported to HHS on 2016-08-22 an Unauthorized Access/Disclosure affecting approximately 15,800 individuals (HHS portal shows 1,000 threshold entry). A departing employee impermissibly copied PHI — including names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment info, Medicaid beneficiary numbers, and SSNs — to an unauthorized USB device on her final days of employment. The breach was detected via CalOptima's data loss prevention system. The CE notified affected individuals, media, and HHS, reported to law enforcement, and implemented corrective actions including disabling USB write privileges for all employees.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Aug 22, 2016
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.