Central California Alliance for Health
ent_bba8077fa0377f26d5bfbc18
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
35,940
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Central California Alliance for Health
- Normalized
- central california alliance for health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ccah-alliance.org
Disclosure history (3)newest first
- 🐻California State AGas victim2021-03-11
Central California Alliance for Health notified members that on May 7, 2020, employee email accounts were accessed illegally by an unknown person for approximately one hour. The incident may have exposed member health information including care management records, claims information, dates of birth, demographic information, Medi-Cal ID numbers, medical information, and referral information. Financial information and SSNs were not included. A revised supplemental notice was issued in January 2021 after additional impacted individuals were identified.
- CALIFORNIAHHS OCRas victim2020-07-02
Central California Alliance for Health (CA Health Plan) reported to HHS on 2020-07-02 a Hacking/IT Incident affecting 35,940 individuals. Several employees fell victim to an email phishing scheme that compromised ePHI including names, addresses, dates of birth, claims information, diagnoses, lab results, and medications. Breached information located in Email. The CE notified HHS, affected individuals, and media, and implemented additional safeguards and employee retraining. OCR provided technical assistance on the HIPAA Security Rule.
- 🐻California State AGas victim2020-07-02
Central California Alliance for Health reported that on May 7, 2020, an unknown person illegally accessed employee email accounts for approximately one hour. Limited member health information, including care management records, claims info, dates of birth, demographic data, Medi-Cal IDs, and medical/referral information, may have been accessed. The organization shut down affected accounts, reset passwords, and mandated security training. No financial information or SSNs were involved.