Kaiser Foundation Healthplan, Inc. of Southern California
ent_52c4c4178e09f97d4f7b2670
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
167,095
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Foundation Healthplan, Inc. of Southern California
- Normalized
- kaiser foundation healthplan inc of southern california— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kaiserpermanente.org
Disclosure history (3)newest first
- California State AGas victim2020-02-28
Kaiser Health Plan, Southern California notified members that an error during a mailing address improvement project caused correspondence to be sent to former addresses between October 6 and December 20, 2019. The error was discovered on November 1, 2019. Affected mailings may have included demographic information, medical information (diagnosis, medication), billing information, and health insurance information. Social Security numbers and credit card information were not included. The organization conducted an investigation, corrected addresses, and is developing staff training to prevent recurrence.
- CALIFORNIAHHS OCRas victim2020-02-06
Kaiser Health Plan, Southern California reported that an employee inadvertently mailed the protected health information (PHI) of 167,095 individuals to the wrong addresses. The PHI included names, addresses, birthdates, diagnoses, lab results, medications, and claims information. The entity notified HHS and affected individuals, implemented additional administrative safeguards, and retrained staff.
- CALIFORNIAHHS OCRas victim2016-11-06
Kaiser Foundation Health Plan, Inc. of Southern California (Kaiser Permanente) reported to HHS OCR on 2016-11-06 an Unauthorized Access/Disclosure affecting 3,044 individuals. An error in the KP website's configuration settings allowed some users to view the PHI of other members. Breached information resided on a Network Server and included names, addresses, dates of birth, claims information, clinical information, financial information, medications prescribed, and other treatment information. KP remediated by creating a corrective action plan, retraining staff, and implementing additional safeguards. OCR provided Security Rule guidance.