DisclosureLens
CALIFORNIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)Medium

Kaiser Permanente Health Plan, Inc of Northern California

bd_e96ca2b27d84425c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jul 12, 2016

To disclose

Affected

1,136

Confidence

50%
Full breach record for Kaiser Permanente Health Plan, Inc of Northern California3 incidents on file

Two former employees of Kaiser Permanente Northern California stole over 2,000 pieces of clinical technology ultrasound units and related parts between June 6, 2010, and May 19, 2016. The breach affected approximately 1,136 patients and included names, internal medical record numbers, and ultrasound images. The entity notified HHS, affected individuals, and the media, and also reported the theft to the FBI. In response, the company trained staff on safeguarding protected health information (PHI) and proper equipment decommissioning, and established new quality assurance processes. The HHS Office for Civil Rights (OCR) provided technical assistance regarding the entity's security management process.

HIPAA clock HHS notified
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.

Incident timeline

Jun 6, 2010

Begins

Jul 12, 2016

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,136 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.