Kaiser Foundation Healthplan, Inc. of Southern California
bd_6adcb341f77b244e · schema v1 · pii pii-v1
Full breach record for Kaiser Foundation Healthplan, Inc. of Southern California →Kaiser Foundation Health Plan, Inc. of Southern California (Kaiser Permanente) reported to HHS OCR on 2016-11-06 an Unauthorized Access/Disclosure affecting 3,044 individuals. An error in the KP website's configuration settings allowed some users to view the PHI of other members. Breached information resided on a Network Server and included names, addresses, dates of birth, claims information, clinical information, financial information, medications prescribed, and other treatment information. KP remediated by creating a corrective action plan, retraining staff, and implementing additional safeguards. OCR provided Security Rule guidance.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 6, 2016
- Raw hash
- 0aeac15637a3e62583c3a678ac95e9f4d856c285df4a62969830e5d86ee34a5c
Source filing
Reporting entity
- Name
- Kaiser Foundation Healthplan, Inc. of Southern Californianorm: kaiser foundation healthplan inc of southern california
- Domain
- kaiserpermanente.org
- Industry
- Insurance — Health
Victim entity
- Name
- Kaiser Foundation Healthplan, Inc. of Southern Californianorm: kaiser foundation healthplan inc of southern california
- Domain
- kaiserpermanente.org
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,044
- Data types
- IDENTITY_BASICHEALTH_BASICFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Regulator citations
- OCR provided Kaiser Permanente with technical guidance regarding the HIPAA Security Rule, including risk analysis and risk management processes and procedures.
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.