DisclosureLens
AccidentalHealthcareFinancial ServicesHealthcareMisdeliveryCustomer Data InvolvedPHIHealth (basic)Identity (basic)LowResolved

Blue Shield of California

bd_da8d40287627423a · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 25, 2025

Filed

Jun 23, 2025

To disclose

8 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

65%

Blue Shield of California disclosed an incident on April 25, 2025, where a customer service agent accidentally filtered a search and emailed protected health information (PHI) belonging to multiple members to an unauthorized recipient. The PHI included names, subscriber IDs, group numbers, account numbers, claim numbers, procedure codes, addresses, and doctor information. No SSNs or financial data were involved. The recipient reported the error immediately. Blue Shield disabled the encryption key, attempted to contact the recipient, educated the employee, and updated procedures. Affected individuals are offered one year of Experian IdentityWorks.

California clockDiscovered Apr 25, 2025 → Notified Jun 23, 202559d ✓ CA 60-day OK8 weeks discovery → filing

Incident timeline

discovery → filing · 8 weeks / 59 days

Apr 25, 2025

Begins

Apr 25, 2025

Discovered

Jun 23, 2025

Filed

vs. sector median

1 wks faster

This filing is one of 2 filings about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRJun 23 · first
California State AGJun 23 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.