California Physicians' Services
bd_a590b256e8ca9708 · schema v1 · pii pii-v1
Full breach record for California Physicians' Services →Blue Shield of California (California Physicians' Service) reported to HHS on 2015-06-09 an Unauthorized Access/Disclosure affecting 843 individuals. On May 18, 2015, a faulty web portal code update allowed authorized users to inadvertently access PHI of individuals outside their line of business. Exposed data included names, addresses, birthdates, and SSNs. The portal was disabled, a patch deployed, and the responsible developer was sanctioned. OCR reviewed the entity's HIPAA Notice of Privacy Practices and confirmed corrective actions. Breached information located on Network Server.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b7e4c7b909039645California State AGfiled 2015-06-05(4d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 9, 2015
- Raw hash
- 8423a21dc117f0e6f21fddd55fabcfbfb906b92e2457037e5ca013df08250637
Source filing
Reporting entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
- Industry
- Insurance — Health
Victim entity
- Name
- California Physicians' Servicesnorm: california physicians
- Domain
- blueshieldca.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- May 18, 2015
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 843
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- OCR reviewed HIPAA Notice of Privacy Practices Policy and obtained assurances of corrective actions.
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 18, 2015→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.