Kaiser Foundation Hospitals
ent_019e10c48f3f02cfafbd882ee7677cf5
Disclosures
5
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
44,600
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Foundation Hospitals
- Normalized
- kaiser foundation hospitals— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- DW4Z57L3G4IRMHYZYK62
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- healthy.kaiserpermanente.org
Disclosure history (5)newest first
- 🐻California State AGas victim2024-11-01
Kaiser Permanente discovered on September 3, 2024, that an unauthorized party accessed the email accounts of two workforce members. The incident occurred between August and September 2024. Affected data included protected health information (PHI) such as names, dates of birth, medical record numbers, and medical information. Social Security numbers and credit card numbers were not involved. Kaiser terminated access and reset passwords.
- CALIFORNIAHHS OCRas victim2024-11-01
Kaiser Foundation Hospitals reported to HHS on 2024-11-01 a Hacking/IT Incident affecting 44,600 individuals. Breached information located on Email. Employees were targeted by an email phishing scheme compromising demographic and clinical PHI. Response included password changes, technical safeguards, and policy revisions.
- 🐻California State AGas victim2021-02-23
Kaiser Foundation Hospitals, Northern California reported an insider incident where an employee inappropriately accessed members' medical records and demographic information. The employee was terminated and policies are being reviewed. No SSN or financial data was involved.
- CALIFORNIAHHS OCRas victim2021-02-23
Kaiser Foundation Hospitals, Northern California reported to HHS on 2021-02-23 a Unauthorized Access/Disclosure affecting 2121 individuals. Breached information located on Electronic Medical Record. An employee impermissibly accessed medical records and ePHI (names, DOB, phone, email, photos). The CE notified HHS, individuals, and media, provided credit monitoring, and sanctioned the employee.
- 🐻California State AGas victim2016-12-20
Kaiser Foundation Hospitals disclosed a data breach involving its online Estimates tool (kp.org) between November 16 and 28, 2016. A system error allowed subsequent users of the tool to view previous users' protected health information, including names, ages, addresses, and financial copay/deductible details. No SSNs or banking information were compromised. The error was discovered on November 28, 2016, and corrected by rolling back the update. The incident is classified as an error/misconfiguration.