Kaiser Permanente Health Plan, Inc of Northern California
ent_079aa78d7a0d8304696a2d5c
Disclosures
4
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,432
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Permanente Health Plan, Inc of Northern California
- Normalized
- kaiser permanente health plan inc of northern california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kp.org
Disclosure history (4)newest first
- California State AGas victim2016-11-07
Kaiser Permanente Health Plan, Inc of Northern California disclosed a misconfiguration error on kp.org during a website upgrade on October 12, 2016. For approximately two hours, protected health information (PHI) viewed by signed-in members may have been mistakenly visible to other visitors. The error was repaired by 1:43 a.m. on October 13, 2016. No Social Security numbers or banking information were disclosed. The organization is updating testing procedures for website updates.
- CALIFORNIAHHS OCRas victim2016-11-07
Kaiser Permanente Health Plan, Inc of Northern California reported to HHS on 2016-11-07 an Unauthorized Access/Disclosure affecting 4432 individuals. Breached information located on Network Server. A website upgrade resulted in an incorrect caching configuration, saving PHI into browser cache accessible to other visitors.
- California State AGas victim2016-07-12
Kaiser Permanente Northern California reported the theft of ultrasound machines by two employees between 2010 and 2016. The stolen devices contained protected health information (PHI), including medical record numbers and patient names. The theft was motivated by profit from selling the equipment, not data misuse. No financial data or SSNs were involved. An investigation is ongoing.
- CALIFORNIAHHS OCRas victim2016-07-12
Two former employees of Kaiser Permanente Northern California stole over 2,000 pieces of clinical technology ultrasound units and related parts between June 6, 2010, and May 19, 2016. The breach affected approximately 1,136 patients and included names, internal medical record numbers, and ultrasound images. The entity notified HHS, affected individuals, and the media, and also reported the theft to the FBI. In response, the company trained staff on safeguarding protected health information (PHI) and proper equipment decommissioning, and established new quality assurance processes. The HHS Office for Civil Rights (OCR) provided technical assistance regarding the entity's security management process.