California Department of Health Care Services
ent_a71b76413a7240b457cbaf77
Disclosures
4
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,460
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Department of Health Care Services
- Normalized
- california department of health care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- CALIFORNIAHHS OCRas victim2023-03-14
California Department of Health Care Services (Health Plan, CA) reported to HHS on 2023-03-14 an Unauthorized Access/Disclosure affecting 6,460 individuals. The covered entity's business associate mailed PHI — including names, birthdates, Social Security numbers, addresses, and clinical information — to the wrong recipients. Breached information located on Paper/Films. The CE notified HHS, affected individuals, and the media. Additional administrative, technical, and security safeguards were implemented in response.
- California State AGas victim2012-12-24
The California Department of Health Care Services (DHCS) experienced a data breach due to a computer programming error during a mailing of Beneficiary Identification Cards (BIC) for Medi-Cal enrollment. Between December 10 and 18, 2012, cards containing children's names, Client Index Numbers, dates of birth, and genders were accidentally mailed to wrong households. DHCS discovered the error on December 19, 2012, and notified affected parents on December 21, 2012. New cards were issued. Social Security Numbers were not included.
- CALIFORNIAHHS OCRas reporting2012-12-23
California Department of Health Care Services (DHCS) reported to HHS on 2012-12-23 an Unauthorized Access/Disclosure affecting 2,643 individuals. Due to a computer programming error in electronic mailing files, 2,705 Medi-Cal member ID cards were mailed to wrong households. PHI on the cards included names, dates of birth, genders, dates of issue, and Medi-Cal-assigned numbers. The CE halted mailings, deactivated and replaced the cards, and implemented new data transfer policies and mailing procedures. OCR obtained assurances of corrective action.
- California State AGas victim2012-12-05
California Department of Healthcare Services reported a data breach to the California Attorney General on November 5, 2012. The filing provides only the occurrence date and organization name; the attached notice PDF is unreadable/redacted, preventing extraction of data types, affected counts, or incident details.