AccidentalMisdeliveryCustomer Data InvolvedIDENTITY_BASICMETADATABEHAVIORLOCATIONLowResolved
KAISER FOUNDATION HEALTH PLAN, INC.
bd_6df8e8fd95107a35 · schema v1 · pii pii-v1
Full breach record for KAISER FOUNDATION HEALTH PLAN, INC. →Kaiser Permanente disclosed that cookies/pixels on its websites and apps may have transmitted member personal information (IP address, name, account status, navigation data, search terms) to third-party vendors Google, Microsoft Bing, and X (Twitter). Credentials, SSNs, and financial data were not involved. The technologies were removed following an internal investigation.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_35c97dbc0b1600c1HHS OCRfiled 2024-04-12Candidate
- bd_c5cf4b16fb2197abOregon State AGfiled 2024-04-12Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583875
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2024
- Raw hash
- 9d6df8bc4168ed2a26968550890377543950528341c49be8b561b8e9b814e999
Reporting entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
Victim entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
Incident
- Discovered
- Oct 25, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICMETADATABEHAVIORLOCATION
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 24 weeks(170 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.