California Physicians' Services
bd_84acd95eb54876f6 · schema v1 · pii pii-v1
Full breach record for California Physicians' Services →Blue Shield of California inadvertently included provider Social Security numbers (SSNs) in public provider rosters submitted to the California Department of Managed Health Care (DMHC) in early 2013. The DMHC discovered the error in May 2014 and found that the rosters, containing names, addresses, and SSNs, had been released in response to ten Public Records Act requests. Blue Shield and the DMHC implemented data loss prevention software and revised submission procedures to prevent recurrence. Affected providers were offered one year of Experian's ProtectMyID identity protection service.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45753
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2014
- Raw hash
- 0ee7057f8dc75dba26290bdf35678b2355f2490395a578f562a5a3fc68d04eda
Reporting entity
- Name
- Department of Managed Health Carenorm: department of managed health care
Victim entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
Incident
- Discovered
- May 16, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Unknown
- Regulator citations
- The DMHC discovered that Blue Shield of California had inadvertently included provider Social Security numbers (SSNs) in the rosters Blue Shield provided to the DMHC in February, March and April, 2013.
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.