Kaiser Permanente Northern California Division of Research
ent_8a7c43c9890031207279580c
Disclosures
2
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
5,178
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kaiser Permanente Northern California Division of Research
- Normalized
- kaiser permanente northern california division of research— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- California State AGas reporting2014-04-02
Kaiser Permanente Northern CA Department of Research discovered on Feb 12, 2014, that a server storing research data was infected with malicious software, believed to have occurred in Oct 2011. The malware compromised security barriers, potentially exposing PHI including names, DOB, gender, address, race/ethnicity, MRN, lab results, and research responses. SSNs and EMRs were not included. No evidence of unauthorized access or exfiltration was found. The server was removed, and authorities were notified.
- CALIFORNIAHHS OCRas victim2014-04-02
Kaiser Permanente Northern California Division of Research reported a breach affecting 5,178 individuals after a malware infection on a computer server. Compromised ePHI included names, dates of birth, gender, address, race/ethnicity, medical record numbers, lab results, and research questionnaire responses. The entity notified HHS, affected individuals, and the media, conducted a security analysis, revised policies, and trained workforce members. OCR provided technical assistance on the HIPAA Security Rule.