CALIFORNIAAccidentalHealthcareHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowResolved
KAISER FOUNDATION HEALTH PLAN, INC.
bd_cb506deae0e6da6d · schema v1 · pii pii-v1
Full breach record for KAISER FOUNDATION HEALTH PLAN, INC. →Kaiser Foundation Health Plan reported to HHS on 2017-10-20 a Unauthorized Access/Disclosure affecting 720 individuals. Breached information located on Paper/Films. A business associate superimposed patient addresses during a batch mailing of outreach letters, resulting in 720 patients receiving letters intended for others. Demographic information (names and addresses) was exposed. Corrective actions included implementing secondary Quality Assurance checks and adding a CE manager for final sign-off.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_cf8d834f17f7de4bCalifornia State AGfiled 2017-10-20Candidate
- bd_cfea281b315d5aa7California State AGfiled 2017-08-31(50d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 20, 2017
- Raw hash
- 230ad6e638ac83853c91e8c7208a61913f0808763e3f29013b23ba93a1cb3dc0
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
- Industry
- Insurance — Health
Victim entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 720
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Provided breach notification to HHSOCR obtained assurances that the CE implemented the corrective actions noted above
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.