CALIFORNIA PHYSICIANS' SERVICE
ent_019fcd6cae626f6bbfc9587dc411e29f
Disclosures
25+
HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
9
incidents joining 2+ filings here
Max affected reported
4,700,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CALIFORNIA PHYSICIANS' SERVICE
- Normalized
- california physicians service— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300LWELUA6Y1JGC97
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- blueshieldca.com
Disclosure history (newest 25)newest first
- CALIFORNIAHHS OCRas reporting2025-09-29
Blue Shield of California reported to HHS on 2025-09-29 a Unauthorized Access/Disclosure affecting 607 individuals. Breached information located on Paper/Films. A coding issue resulted in PHI (names, DOBs, SSNs) being mailed to the wrong individuals. The BA fixed the coding issue and provided free credit monitoring.
- CALIFORNIAHHS OCRas reporting2025-09-29
Blue Shield of California (Health Plan, CA) reported to HHS on 2025-09-29 an Unauthorized Access/Disclosure affecting 93,921 individuals. An employee mailed PHI — comprising demographic information — to wrong addresses. Breached information was on Paper/Films. No business associate was involved. The CE notified HHS, affected individuals, and the media, provided complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- California State AGas reporting2025-07-21
Blue Shield of California reported a data security breach to the California Attorney General. The incident occurred between March 25, 2025, and May 22, 2025. The filing includes a sample member notification letter but the provided text extraction of the letter is redacted/empty, preventing extraction of specific data types, affected counts, or response actions. The organization is a healthcare insurer.
- CALIFORNIAHHS OCRas reporting2025-07-21
Blue Shield of California (CA Health Plan) reported to HHS OCR on 2025-07-21 an Unauthorized Access/Disclosure incident affecting 783 individuals. Breached information was located on Laptop, Network Server, and Other media. No business associate was identified as present. No further detail was provided in the web description.
- CALIFORNIAHHS OCRas reporting2025-06-23
Blue Shield of California (Business Associate, CA) reported to HHS OCR on 2025-06-23 an Unauthorized Access/Disclosure breach affecting 673 individuals. The breached information was located in Email. A business associate was present. No further detail was available from the web description.
- California State AGas reporting2025-06-23
Blue Shield of California disclosed an incident on April 25, 2025, where a customer service agent accidentally filtered a search and emailed protected health information (PHI) belonging to multiple members to an unauthorized recipient. The PHI included names, subscriber IDs, group numbers, account numbers, claim numbers, procedure codes, addresses, and doctor information. No SSNs or financial data were involved. The recipient reported the error immediately. Blue Shield disabled the encryption key, attempted to contact the recipient, educated the employee, and updated procedures. Affected individuals are offered one year of Experian IdentityWorks.
- CALIFORNIAHHS OCRas reporting2025-06-06
Blue Shield of California reported to HHS on 2025-06-06 a Unauthorized Access/Disclosure affecting 1543 individuals. Breached information located on Other. Business associate present: Yes.
- California State AGas reporting2025-06-06
Blue Shield of California experienced a data breach due to an incorrect data merge in its Member Health Record portal feature. From June 27, 2024, to April 4, 2025, some members could potentially view another member's protected health information, including visit dates, medications, immunizations, allergies, lab results, and diagnoses. The issue was identified on April 4, 2025, and the feature was immediately suppressed. No evidence suggests the data was downloaded or misused. Affected individuals are offered one year of Experian IdentityWorks.
- CALIFORNIAHHS OCRas reporting2025-04-09
Blue Shield of California reported to HHS on 2025-04-09 a Unauthorized Access/Disclosure affecting 4,700,000 individuals. Breached information located on Network Server. Google Analytics was misconfigured, transmitting PHI to Google.
- California State AGas reporting2025-04-09
Blue Shield of California disclosed a misconfiguration in Google Analytics that allowed protected health information (PHI) to be shared with Google Ads between April 2021 and January 2024. The issue was discovered on February 11, 2025. Affected data includes insurance plan details, medical claim service dates, provider names, and patient financial responsibility. No malicious actor was involved; the exposure resulted from a vendor configuration error. Blue Shield severed the connection and reviewed security protocols.
- California State AGas reporting2025-03-28
Blue Shield of California notified members that a data mismatch error in a health information exchange feed allowed family members on the same plan to potentially view each other's health records (visit types, dates, providers, medications) via the Member Portal between Oct 28 and Nov 11, 2024. The issue was identified on Nov 8, 2024, and the data feed was terminated on Nov 11, 2024. No demographic identifiers, SSNs, or financial data were exposed.
- CALIFORNIAHHS OCRas reporting2025-02-28
Blue Shield of California reported to HHS on 2025-02-28 an Unauthorized Access/Disclosure affecting 624 individuals. Due to a configuration error, PHI including medications and other treatment information was viewable by others via the Internet through an Electronic Medical Record system. The CE notified HHS, affected individuals, and the media, and provided free credit monitoring.
- California State AGas reporting2024-01-04
Welltok, Inc., a third-party service provider for Blue Shield of California, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023. The incident affects Blue Shield members. Welltok is offering credit monitoring services.
- New Hampshire State AGas victim2023-11-22
Medical Eye Services (vendor) exploited MOVEit vulnerability on Aug 23, 2023, affecting Blue Shield of California (victim). Data exfiltrated May 28-31, 2023. Incident reported to FBI. Notifications mailed Nov 17, 2023 to NH residents. Data included names, SSNs, DOBs. Remediation: system rebuild, credit monitoring offered.
- CALIFORNIAHHS OCRas victim2023-11-17
California Physicians’ Service d/b/a Blue Shield of California reported to HHS on 2023-11-17 a Hacking/IT Incident affecting 636,849 individuals. Breached information located on Network Server. A business associate experienced a cyber-attack compromising PHI including names, SSNs, diagnoses, addresses, birthdates, and claims. The CE provided credit monitoring and implemented additional safeguards.
- California State AGas reporting2023-11-17
Blue Shield of California notified members that a contracted vendor managing vision benefits was compromised in the global MOVEit data security incident. An unauthorized third party exploited an unknown vulnerability in the MOVEit server to exfiltrate information on May 28 and May 31, 2023. The vendor discovered the breach on August 23, 2023. Affected data may include member eligibility, authorized third parties, and vision claims processing information. Blue Shield is offering complimentary credit monitoring and identity restoration services through Kroll.
- Massachusetts State AGas reporting2023-07-21
Blue Shield of California reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-21. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- CALIFORNIAHHS OCRas reporting2023-04-05
California Physicians' Services dba Blue Shield of California reported to HHS on 2023-04-05 a Hacking/IT Incident affecting 1,553 individuals. The breach occurred at a subcontractor of the covered entity's business associate, impacting PHI stored on a network server. PHI exposed included names, dates of birth, and addresses. The CE severed connections to affected servers, implemented additional technical safeguards, and offered credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas reporting2023-04-04
California Physicians' Services d/b/a Blue Shield of California reported to HHS on 2023-04-04 a Hacking/IT Incident affecting 61,788 individuals. Breached information located on Network Server. The incident involved a business associate's subcontractor. PHI included names, dates of birth, and addresses.
- California State AGas reporting2023-03-31
Blue Shield of California notified members that a third-party subcontractor, Fortra, LLC, suffered a cybersecurity incident between January 28-31, 2023. An unauthorized individual accessed Fortra's GoAnywhere MFTaaS application and potentially exfiltrated files maintained by Blue Shield's provider, Brightline Medical Associates. Affected data included names, addresses, dates of birth, gender, subscriber IDs, phone numbers, emails, and plan information. No SSNs or financial data were accessed. Blue Shield locked communications with Brightline and offered one year of Experian IdentityWorks.
- Maine State AGas reporting2023-03-27
Blue Shield of California, acting as a business associate, experienced an external system breach (hacking) from January 28, 2023, to January 31, 2023. The incident was discovered on January 30, 2023. The breach affected 44 Maine residents, who were notified via written communication on March 27, 2023. The company offered one year of complimentary credit monitoring and identity theft restoration services to those affected.
- Maine State AGas reporting2022-12-29
California Physicians' Services d/b/a Blue Shield of California (BSC) reported an insider wrongdoing incident occurring between June 17, 2022, and October 30, 2022. The breach compromised names and Social Security Numbers of 3,411 individuals, including one Maine resident. BSC notified affected individuals in writing on December 22, 2022, and offered one year of credit monitoring through Experian IdentityWorks.
- Massachusetts State AGas reporting2022-12-22
California Physicians' Services d/b/a Blue Shield of California reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-12-22. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas reporting2022-12-22
California Physicians' Services dba Blue Shield of California reported a data breach to the Indiana Attorney General. The breach occurred on 2022-06-17 and was reported on 2022-12-22. 1 Indiana residents were affected. 3,411 individuals affected in total.
- California State AGas reporting2022-07-12
Blue Shield of California notified members of a ransomware attack on OneTouchPoint (OTP), a subcontractor of vendor Matrix Medical Network. OTP detected suspicious network activity on April 28, 2022; Blue Shield learned of the incident on May 20, 2022. Affected members' PHI may have included names, subscriber IDs, diagnoses, medications, addresses, and other health data. No SSNs, driver's licenses, or financial data were accessed. One year of Experian IdentityWorks was offered.
Supply-chain cascadesreviewed and confirmed
- CALIFORNIA PHYSICIANS' SERVICE’s filing is one of at least 8 in the Welltok supply-chain incident (2023).
- CALIFORNIA PHYSICIANS' SERVICE’s filing is one of at least 12 in the FORTRA, LLC supply-chain incident (2023).
- CALIFORNIA PHYSICIANS' SERVICE’s filing is one of at least 3 in the OneDigital Investment Advisors LLC supply-chain incident (2021).
- CALIFORNIA PHYSICIANS' SERVICE’s filing is one of at least 4 in the Sharecare Health Data Services, LLC supply-chain incident (2019).