Kaiser Permanente Northern CA Department of Research
bd_538198849343e32f · schema v1 · pii pii-v1
Kaiser Permanente Northern CA Department of Research discovered on Feb 12, 2014, that a server storing research data was infected with malicious software, believed to have occurred in Oct 2011. The malware compromised security barriers, potentially exposing PHI including names, DOB, gender, address, race/ethnicity, MRN, lab results, and research responses. SSNs and EMRs were not included. No evidence of unauthorized access or exfiltration was found. The server was removed, and authorities were notified.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2011
Begins
Feb 12, 2014
Discovered
Apr 2, 2014
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_8ffbadbfd13002d12014-04-02Candidate
Filing propagation · 2 filings
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.