Blue Shield of California (BSC)
ent_53de77e4ae5d91c574631579
Disclosures
6
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
2,962
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Blue Shield of California (BSC)
- Normalized
- blue shield of california bsc— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Illinois State AGas victim2025-05-01
BLUE SHIELD OF CALIFORNIA filed a data-breach notice with the Illinois Attorney General in May 2025 (case 25-05-157). The register records the breach as discovered on February 11, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Washington State AGas victim2023-11-17
Blue Shield of California, a health insurer, notified affected individuals of a data breach involving its contracted vision benefits vendor. The vendor's MOVEit server was compromised via an unknown vulnerability, leading to data exfiltration between May 28-31, 2023. Blue Shield discovered the incident on August 23, 2023. Affected data included names and government IDs. 2,962 Washington residents were notified.
- Montana State AGas reporting2023-11-17
Blue Shield of California notified Montana residents of a data breach involving a third-party vision benefits vendor. The vendor exploited an unknown vulnerability in MOVEit to exfiltrate data on May 28-31, 2023. Blue Shield discovered the incident on August 23, 2023. Affected data likely includes names and government IDs. Blue Shield offered credit monitoring via Kroll.
- California State AGas victim2022-12-22
Blue Shield of California notified the California AG that an employee emailed a confidential spreadsheet containing insurance brokers' PII (including SSN/TIN, name, address, phone, email) to a personal email address on June 17, 2022, and again on October 30, 2022. The incident was discovered on October 30, 2022. The employee's access was disabled, and they were directed to delete the data. Blue Shield is strengthening detection tools and offering one year of credit monitoring.
- Montana State AGas victim2022-12-22
Blue Shield of California notified Montana residents that an employee emailed a confidential spreadsheet containing brokers' PII (name, SSN/TIN, address, phone, email) to a personal email account on June 17 and October 30, 2022. Blue Shield disabled the employee's access, interviewed them, and directed deletion of the data. The company is offering one year of credit monitoring and identity restoration services.
- Illinois State AGas victim2019-01-01
BLUE SHIELD OF CALIFORNIA filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-278). The register records the breach as discovered on July 5, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.