HackingPhishingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
KAISER FOUNDATION HEALTH PLAN, INC.
bd_d3464dee73afcd80 · schema v1 · pii pii-v1
Full breach record for KAISER FOUNDATION HEALTH PLAN, INC. →Kaiser Foundation Health Plan, Inc. reported a data breach affecting its email system containing protected health information (PHI). The incident, discovered on November 13, 2017, involved unauthorized access to patient records including names, medical record numbers, diagnoses, and dates of birth. No Social Security numbers or financial information were compromised. Kaiser launched an investigation and notified government agencies.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_154a5879c8b6a559HHS OCRfiled 2017-12-14(9d gap)Verified
- bd_649d83bc98b2cad4HHS OCRfiled 2017-12-22(17d gap)Verified
- bd_d3fa6585fbb921e8California State AGfiled 2017-12-28(23d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-119507
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 5, 2017
- Raw hash
- 943ac6e0350d7b3586cba8c9337d19cafcae1ef837a7d0e8a272ce2947adb245
Reporting entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
Victim entity
- Name
- KAISER FOUNDATION HEALTH PLAN, INC.norm: kaiser foundation health plan
- Domain
- healthy.kaiserpermanente.org
Incident
- Discovered
- Nov 13, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1114 Email Collection
- Threat actor
- External
- Regulator citations
- notification of government agencies as required
- Initial access
- phishing_link
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.