Central California Alliance for Health
ent_bba8077fa0377f26d5bfbc18
Disclosures
3
State AG · HHS OCR · 1 jurisdiction
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
35,940
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Central California Alliance for Health
- Normalized
- central california alliance for health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ccah-alliance.org
Disclosure history (3)newest first
- California State AGas victim2021-03-11
Central California Alliance for Health reported that an unknown person illegally accessed employee email accounts between April 28 and May 8, 2020. The breach was discovered on May 7, 2020. Affected data included limited member health information such as claims, Medi-Cal IDs, and demographic data. The organization shut down affected accounts, reset passwords, and provided security training.
- CALIFORNIAHHS OCRas victim2020-07-02
Central California Alliance for Health (CA Health Plan) reported to HHS on 2020-07-02 a Hacking/IT Incident affecting 35,940 individuals. Several employees fell victim to an email phishing scheme that compromised ePHI including names, addresses, dates of birth, claims information, diagnoses, lab results, and medications. Breached information located in Email. The CE notified HHS, affected individuals, and media, and implemented additional safeguards and employee retraining. OCR provided technical assistance on the HIPAA Security Rule.
- California State AGas victim2020-07-02
Central California Alliance for Health reported that on May 7, 2020, an unknown person illegally accessed employee email accounts for approximately one hour. Limited member health information, including care management records, claims info, dates of birth, demographic data, Medi-Cal IDs, and medical/referral information, may have been accessed. The organization shut down affected accounts, reset passwords, and mandated security training. No financial information or SSNs were involved.