KAISER PERMANENTE GROUP TRUST
ent_019e09bae46e621f5a439c393d4554b8
Disclosures
5
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
15,500
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- KAISER PERMANENTE GROUP TRUST
- Normalized
- kaiser permanente— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- HZJYWC3G72NF1FLBKF14
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kaiserpermanente.org
Disclosure history (5)newest first
- 🐻California State AGas victim2019-09-26
Kaiser Permanente notified members that a provider's email account containing protected health information was compromised by an unknown individual for approximately 13 hours on August 12, 2019. The incident was discovered on August 19, 2019. Affected data included names, medical record numbers, dates of service, diagnoses, and treatment details. Social Security numbers and financial information were not involved. Kaiser changed the account password and strengthened email security controls.
- CALIFORNIAHHS OCRas victim2019-09-26
Kaiser Permanente (Oakland, CA) reported to HHS on 2019-09-26 a Hacking/IT Incident — email phishing scheme — affecting 990 individuals. An employee was the victim of a phishing attack that exposed ePHI including names, birthdates, gender, diagnoses, health insurance information, clinical information, and other treatment information. Breached information located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards. OCR provided technical assistance regarding the HIPAA Security Rule.
- 🐻California State AGas victim2012-10-29
Kaiser Permanente mistakenly emailed a list of former Northern California employees, including names and Social Security numbers, to an unauthorized recipient on August 24, 2012. The incident was discovered in late August 2012. Investigation confirmed the recipient deleted the data and did not further distribute it. No personal health information was involved. New controls were implemented to prevent recurrence.
- 🐻California State AGas victim2012-04-16
On April 6, 2012, a Kaiser Permanente employee inadvertently sent a surgical procedure report containing PHI (name, medical record number, surgery type, surgeon name, date) to a non-Kaiser email address. The report required specialized software to read. Kaiser contacted the recipient to confirm deletion. No SSN was included.
- FEDERALHHS OCRas victim2010-01-12
Kaiser Permanente Medical Care Program reported to HHS on 2010-01-12 a Theft affecting 15500 individuals. An unencrypted portable hard drive with patient ePHI was stolen from an employee's vehicle. Breached information was located on Other, Other Portable Electronic Device.