KAISER FOUNDATION HEALTH PLAN, INC.
ent_019e0b098f49a8299499980619c81405
Disclosures
19
State AG · HHS OCR · 4 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
13,400,000
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- KAISER FOUNDATION HEALTH PLAN, INC.
- Normalized
- kaiser foundation health plan— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- XG5W89ON10795WH3SB26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- healthy.kaiserpermanente.org
Disclosure history (19)newest first
- 🌲Washington State AGas victim2024-06-03
Kaiser Foundation Health Plan, Inc. (Philips Respironics, Inc.), a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2024-06-03. 17,530 Washington residents were affected. 369 days elapsed between awareness and notification. 0 days to identify the breach. 5 days to contain the breach.
- CALIFORNIAHHS OCRas victim2024-04-12
Kaiser Foundation Health Plan, Inc. (CA) reported to HHS on 2024-04-12 an Unauthorized Access/Disclosure affecting up to 13,400,000 individuals. The CE disclosed PHI — including clinical, demographic, and financial information — while using third-party tracking technologies embedded in its authenticated online platforms. Location of breached information: Network Server. In response, Kaiser removed all third-party tracking technologies, retrained workforce members, and implemented additional administrative safeguards. The CE notified HHS, affected individuals, and the media.
- 🐻California State AGas victim2024-04-12
Kaiser Permanente disclosed that cookies/pixels on its websites and apps may have transmitted member personal information (IP address, name, account status, navigation data, search terms) to third-party vendors Google, Microsoft Bing, and X (Twitter). Credentials, SSNs, and financial data were not involved. The technologies were removed following an internal investigation.
- 🦫Oregon State AGas victim2024-04-12
Kaiser Foundation Health Plan, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-04-12. 13,400,000 individuals were affected.
- CALIFORNIAHHS OCRas victim2022-11-17
Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc. reported to HHS on 2022-11-17 a Unauthorized Access/Disclosure affecting 8556 individuals. Breached information located on Electronic Medical Record.
- 🐻California State AGas victim2022-07-15
Kaiser Permanente discovered on May 20, 2022, that an iPad containing photos of COVID-19 lab specimen labels was stolen from a locked storage area at the Los Angeles Medical Center. The photos potentially contained first name, last name, medical record number, date of birth, and date/location of service for affected individuals. No SSNs or credit card numbers were involved. The device was remotely wiped, and law enforcement was notified.
- CALIFORNIAHHS OCRas victim2022-04-06
Kaiser Foundation Health Plan reported that a business associate exposed PHI (names and financial information) of 695 individuals by making the data viewable to others on a network server. The covered entity notified HHS, affected individuals, and the media, posted substitute notice, and implemented additional administrative and technical safeguards.
- MARYLANDHHS OCRas victim2020-05-22
Kaiser Foundation Health Plan of the Mid-Atlantic States reported to HHS on 2020-05-22 a Unauthorized Access/Disclosure affecting 2756 individuals. Breached information located on Electronic Medical Record.
- 🐻California State AGas victim2017-12-28
On October 9, 2017, Kaiser Foundation Health Plan inadvertently mailed a letter containing a member's protected health information (name and prescription medication) to another Kaiser Permanente member. The incident was reported to the California AG. No SSN, Medical Record Number, or financial information was disclosed. The incident was under review per Kaiser Permanente's policies.
- CALIFORNIAHHS OCRas victim2017-12-22
Kaiser Foundation Health Plan, Inc. reported to HHS on 2017-12-22 a Unauthorized Access/Disclosure affecting 638 individuals. Breached information located on Paper/Films. The breach involved impermissible disclosure of PHI (names, medications) due to a mail merge quality assurance flaw.
- CALIFORNIAHHS OCRas victim2017-12-14
Kaiser Foundation Health Plan, Inc. reported to HHS on 2017-12-14 a Hacking/IT Incident affecting 4389 individuals. Breached information located on Email. A physician's Outlook account was accessed using compromised credentials, exposing PHI including demographic, clinical, and claims data.
- 🐻California State AGas victim2017-12-05
Kaiser Foundation Health Plan, Inc. reported a data breach affecting its email system containing protected health information (PHI). The incident, discovered on November 13, 2017, involved unauthorized access to patient records including names, medical record numbers, diagnoses, and dates of birth. No Social Security numbers or financial information were compromised. Kaiser launched an investigation and notified government agencies.
- CALIFORNIAHHS OCRas victim2017-10-20
Kaiser Foundation Health Plan reported to HHS on 2017-10-20 a Unauthorized Access/Disclosure affecting 720 individuals. Breached information located on Paper/Films. A business associate superimposed patient addresses during a batch mailing of outreach letters, resulting in 720 patients receiving letters intended for others. Demographic information (names and addresses) was exposed. Corrective actions included implementing secondary Quality Assurance checks and adding a CE manager for final sign-off.
- 🐻California State AGas victim2017-10-20
Kaiser Foundation Health Plan, Inc. notified members that a letter intended for one member was inadvertently mailed to another. The letter referenced the Liver Care Program and contained the member's first and last name and medical record number. No financial data or other medical information was involved. The organization is reviewing internal processes to prevent recurrence.
- 🐻California State AGas victim2017-08-31
On August 9, 2017, Kaiser Foundation Health Plan inadvertently emailed a document containing protected health information (name, medical record number, procedure, and date of service) to an unknown external email address. The incident was classified as an inadvertent error with no evidence of hacking or bad intent. Notification was sent on August 30, 2017.
- CALIFORNIAHHS OCRas victim2016-04-22
On March 12, 2016, Kaiser Foundation Health Plan, Inc. (CA) discovered that a truck belonging to its business associate Postage One was stolen, and a pallet of printed 'evidence of coverage' booklets for Inland Empire Health Plan members was missing. The booklets contained names, addresses, and a generic overview of covered benefits for 2,451 individuals. Breach notification was submitted to HHS on 2016-04-22. Remediation included revised mail security policies and workforce training. Breached information located on Paper/Films.
- MARYLANDHHS OCRas victim2015-01-29
Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc. reported to HHS on 2015-01-29 a Unauthorized Access/Disclosure affecting 630 individuals. Breached information located on Paper/Films. Due to a printing error, patients received appointment reminders containing other patients’ protected health information (PHI), including names, medical record numbers, appointment types, and provider information. Additional safeguards were implemented to prevent future disclosures.
- 🐻California State AGas victim2013-09-11
Kaiser Foundation Health Plan, Inc. reported an accidental email disclosure of confidential member information on May 16, 2013. The incident involved the transmission of a file containing names, medical record numbers, contact details, and employer data to an unauthorized recipient. The error was discovered in late July 2013. The file was deleted, and no screening results were exposed.
- 🐻California State AGas victim2012-03-16
Kaiser Foundation Health Plan disclosed a breach of confidential employee information found on a non-Kaiser Permanente external hard drive purchased second-hand. The data included names, Social Security Numbers, dates of birth, and addresses. The breach was brought to attention in late September 2011. The investigation is ongoing. One year of credit monitoring is being provided.