MalwareData ExfiltratedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Kaiser Permanente Northern California Division of Research
bd_538198849343e32f · schema v1 · pii pii-v1
Full breach record for Kaiser Permanente Northern California Division of Research →Kaiser Permanente Northern CA Department of Research notified California regulators of a cybersecurity incident involving a research server infected with malicious software between October 2011 and February 2014. The breach potentially exposed patient research data including names, dates of birth, and medical record numbers, though SSNs were excluded. No unauthorized access was confirmed, but the server was removed and authorities alerted.
California clockDiscovered Feb 12, 2014 → Notified Apr 3, 201450d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8ffbadbfd13002d1HHS OCRfiled 2014-04-02Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-44690
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2014
- Raw hash
- bdd2b245881fca56ca2f2ce28b287967101ae6634104f49854622a66b725102d
Reporting entity
- Name
- Kaiser Permanente Northern California Division of Researchnorm: kaiser permanente northern california division of research
Victim entity
- Name
- Kaiser Permanente Northern California Division of Researchnorm: kaiser permanente northern california division of research
Incident
- Discovered
- Feb 12, 2014
- Materiality determined
- —
- Notification sent
- Apr 3, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- alerted the appropriate State and federal authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 50d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 12, 2014→ Notified: Apr 3, 201450d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.