Blue Shield of California
bd_da8d40287627423a · schema v1 · pii pii-v1
Blue Shield of California disclosed an incident on April 25, 2025, where a customer service agent accidentally filtered a search and emailed protected health information (PHI) belonging to multiple members to an unauthorized recipient. The PHI included names, subscriber IDs, group numbers, account numbers, claim numbers, procedure codes, addresses, and doctor information. No SSNs or financial data were involved. The recipient reported the error immediately. Blue Shield disabled the encryption key, attempted to contact the recipient, educated the employee, and updated procedures. Affected individuals are offered one year of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 25, 2025
Begins
Apr 25, 2025
Discovered
Jun 23, 2025
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_a1943989c510a3622025-06-23Verified by operator
Filing propagation · 2 filings
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.