CalOptima
ent_166517b4f40f11fa44b50aea
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,000
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CalOptima
- Normalized
- caloptima— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- caloptima.org
Disclosure history (3)newest first
- California State AGas victim2021-10-27
CalOptima disclosed that between August 4 and August 19, 2021, COVID-19 Vaccine Health Reward Approval letters and gift cards were mailed to incorrect addresses due to a failure to match member names with addresses. The exposed information included first and last name, health plan name, and vaccination status. No SSNs or financial data were involved. CalOptima contacted recipients of erroneous letters, re-mailed correct letters, and implemented a secondary address verification step in their mailing process.
- California State AGas victim2016-10-14
On August 17, 2016, a departing CalOptima employee downloaded protected health information, including names, demographic data, and social security numbers for some members (including minors), to an unencrypted USB flash drive. The drive was returned to CalOptima. The organization is investigating the contents and does not believe the information was shared. CalOptima is offering credit/identity monitoring services to affected individuals.
- CALIFORNIAHHS OCRas victim2016-08-22
CalOptima (CA Health Plan) reported to HHS on 2016-08-22 an Unauthorized Access/Disclosure affecting approximately 15,800 individuals (HHS portal shows 1,000 threshold entry). A departing employee impermissibly copied PHI — including names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment info, Medicaid beneficiary numbers, and SSNs — to an unauthorized USB device on her final days of employment. The breach was detected via CalOptima's data loss prevention system. The CE notified affected individuals, media, and HHS, reported to law enforcement, and implemented corrective actions including disabling USB write privileges for all employees.