Kaiser Foundation Healthplan, Inc. of Southern California
ent_52c4c4178e09f97d4f7b2670
Disclosures
3
State AG · HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
167,095
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Foundation Healthplan, Inc. of Southern California
- Normalized
- kaiser foundation healthplan inc of southern california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kaiserpermanente.org
Disclosure history (3)newest first
- 🐻California State AGas victim2020-02-28
Kaiser Health Plan, Southern California, reported a privacy breach involving the misdelivery of mail containing PHI and PII (names, addresses, diagnosis, billing, health insurance info) to former addresses between Oct 6 and Dec 20, 2019. Discovered Nov 1, 2019, the error was corrected Dec 20, 2019. No SSN or credit card data was included. No fraud detected. Staff training is being developed.
- FEDERALHHS OCRas victim2020-02-06
Kaiser Health Plan, Southern California reported that an employee inadvertently mailed the protected health information (PHI) of 167,095 individuals to the wrong addresses. The PHI included names, addresses, birthdates, diagnoses, lab results, medications, and claims information. The entity notified HHS and affected individuals, implemented additional administrative safeguards, and retrained staff.
- CALIFORNIAHHS OCRas victim2016-11-06
Kaiser Foundation Health Plan, Inc. of Southern California (Kaiser Permanente) reported to HHS OCR on 2016-11-06 an Unauthorized Access/Disclosure affecting 3,044 individuals. An error in the KP website's configuration settings allowed some users to view the PHI of other members. Breached information resided on a Network Server and included names, addresses, dates of birth, claims information, clinical information, financial information, medications prescribed, and other treatment information. KP remediated by creating a corrective action plan, retraining staff, and implementing additional safeguards. OCR provided Security Rule guidance.