Kaiser Permanente Health Plan, Inc of Northern California
ent_079aa78d7a0d8304696a2d5c
Disclosures
3
State AG · HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,136
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Permanente Health Plan, Inc of Northern California
- Normalized
- kaiser permanente health plan inc of northern california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kp.org
Disclosure history (3)newest first
- 🐻California State AGas victim2016-11-07
Kaiser Permanente Health Plan, Inc of Northern California disclosed a misconfiguration error on kp.org during a website upgrade on October 12, 2016. For approximately two hours, protected health information (PHI) viewed by signed-in members may have been mistakenly visible to other visitors. The error was repaired by 1:43 a.m. on October 13, 2016. No Social Security numbers or banking information were disclosed. The organization is updating testing procedures for website updates.
- 🐻California State AGas victim2016-07-12
Kaiser Permanente Northern California reported the theft of ultrasound machines containing Protected Health Information (PHI) and Member Reference Numbers (MRN). Two employees stole equipment from multiple sites between 2010 and 2016. The incident was reported to law enforcement. No financial information or SSNs were involved.
- FEDERALHHS OCRas victim2016-07-12
Two former employees of Kaiser Permanente Northern California stole over 2,000 pieces of clinical technology ultrasound units and related parts between June 6, 2010, and May 19, 2016. The breach affected approximately 1,136 patients and included names, internal medical record numbers, and ultrasound images. The entity notified HHS, affected individuals, and the media, and also reported the theft to the FBI. In response, the company trained staff on safeguarding protected health information (PHI) and proper equipment decommissioning, and established new quality assurance processes. The HHS Office for Civil Rights (OCR) provided technical assistance regarding the entity's security management process.