Health Plan of San Mateo
ent_39c17445ef240d5d70996ff2
Disclosures
3
HHS OCR · State AG · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
11,894
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Health Plan of San Mateo
- Normalized
- health plan of san mateo— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- CALIFORNIAHHS OCRas victim2023-03-17
Health Plan of San Mateo (CA) reported to HHS OCR on 2023-03-17 a Hacking/IT Incident (email phishing) affecting 11,894 individuals. An employee was the subject of an email phishing scheme that exposed PHI including names, dates of birth, diagnoses/conditions, medications, and other treatment information. Breached information located in Email. No business associate was involved. The CE notified HHS, affected individuals, the media, and posted a substitute notice. Additional administrative, technical, and security safeguards were implemented.
- 🐻California State AGas victim2023-03-17
Health Plan of San Mateo disclosed an email phishing incident on January 17, 2023, where an unauthorized person accessed one employee email account. The attacker attempted to fraudulently change direct deposit information. A spreadsheet containing member names, dates of birth, member IDs, and limited nurse advice line call information was potentially exposed. No SSNs or financial data were involved. The company engaged a cybersecurity firm, reviewed the mailbox, enhanced security measures, and provided employee training.
- CALIFORNIAHHS OCRas victim2011-06-29
Health Plan of San Mateo reported to HHS on 2011-06-29 a Unauthorized Access/Disclosure affecting 694 individuals. Breached information located on Paper/Films.