Kaiser Permanente Health Plan, Inc of Northern California
bd_e96ca2b27d84425c · schema v1 · pii pii-v1
Full breach record for Kaiser Permanente Health Plan, Inc of Northern California →Two former employees of Kaiser Permanente Northern California stole over 2,000 pieces of clinical technology ultrasound units and related parts between June 6, 2010, and May 19, 2016. The breach affected approximately 1,136 patients and included names, internal medical record numbers, and ultrasound images. The entity notified HHS, affected individuals, and the media, and also reported the theft to the FBI. In response, the company trained staff on safeguarding protected health information (PHI) and proper equipment decommissioning, and established new quality assurance processes. The HHS Office for Civil Rights (OCR) provided technical assistance regarding the entity's security management process.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 12, 2016
- Raw hash
- b960a0ee5ba592a7e7cf0db4872343d9ebb453f901fae5f41e993dfa35f65e42
Source filing
Reporting entity
- Name
- Kaiser Permanente Health Plan, Inc of Northern Californianorm: kaiser permanente health plan inc of northern california
- Domain
- kp.org
- Industry
- Insurance — Health
Victim entity
- Name
- Kaiser Permanente Health Plan, Inc of Northern Californianorm: kaiser permanente health plan inc of northern california
- Domain
- kp.org
- Industry
- Insurance — Health
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,136
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Internal
- Regulator citations
- Notified HHSReported to FBIOCR provided technical assistance
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.