California Physicians' Services
ent_bd3e836b3117bb0e0eae10fc
Disclosures
25+
HHS OCR · State AG · 2 jurisdictions
Incidents
7
filings grouped by incident
Max affected reported
93,921
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- California Physicians' Services
- Normalized
- california physicians— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001S3RQ3VTIVNP03
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- blueshieldca.com
Disclosure history (newest 25)newest first
- CALIFORNIAHHS OCRas victim2025-09-29
Blue Shield of California reported to HHS on 2025-09-29 a Unauthorized Access/Disclosure affecting 607 individuals. Breached information located on Paper/Films. A coding issue resulted in PHI (names, DOBs, SSNs) being mailed to the wrong individuals. The BA fixed the coding issue and provided free credit monitoring.
- CALIFORNIAHHS OCRas victim2025-09-29
Blue Shield of California (Health Plan, CA) reported to HHS on 2025-09-29 an Unauthorized Access/Disclosure affecting 93,921 individuals. An employee mailed PHI — comprising demographic information — to wrong addresses. Breached information was on Paper/Films. No business associate was involved. The CE notified HHS, affected individuals, and the media, provided complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- 🐻California State AGas victim2025-07-21
Blue Shield of California reported a data security breach to the California Attorney General. The incident occurred between March 25, 2025, and May 22, 2025. The filing includes a sample member notification letter but the provided text extraction of the letter is redacted/empty, preventing extraction of specific data types, affected counts, or response actions. The organization is a healthcare insurer.
- CALIFORNIAHHS OCRas victim2025-07-21
Blue Shield of California (CA Health Plan) reported to HHS OCR on 2025-07-21 an Unauthorized Access/Disclosure incident affecting 783 individuals. Breached information was located on Laptop, Network Server, and Other media. No business associate was identified as present. No further detail was provided in the web description.
- CALIFORNIAHHS OCRas victim2025-06-23
Blue Shield of California (Business Associate, CA) reported to HHS OCR on 2025-06-23 an Unauthorized Access/Disclosure breach affecting 673 individuals. The breached information was located in Email. A business associate was present. No further detail was available from the web description.
- 🐻California State AGas victim2025-06-23
Blue Shield of California disclosed an incident on April 25, 2025, where a customer service agent accidentally filtered a search and emailed protected health information (PHI) belonging to multiple members to an unauthorized recipient. The PHI included names, subscriber IDs, group numbers, account numbers, claim numbers, procedure codes, addresses, and doctor information. No SSNs or financial data were involved. The recipient reported the error immediately. Blue Shield disabled the encryption key, attempted to contact the recipient, educated the employee, and updated procedures. Affected individuals are offered one year of Experian IdentityWorks.
- CALIFORNIAHHS OCRas victim2025-06-06
Blue Shield of California reported to HHS on 2025-06-06 a Unauthorized Access/Disclosure affecting 1543 individuals. Breached information located on Other. Business associate present: Yes.
- 🐻California State AGas victim2025-06-06
Blue Shield of California experienced a data breach due to an incorrect data merge in its Member Health Record portal feature. From June 27, 2024, to April 4, 2025, some members could potentially view another member's protected health information, including visit dates, medications, immunizations, allergies, lab results, and diagnoses. The issue was identified on April 4, 2025, and the feature was immediately suppressed. No evidence suggests the data was downloaded or misused. Affected individuals are offered one year of Experian IdentityWorks.
- 🐻California State AGas victim2025-04-09
Blue Shield of California disclosed a misconfiguration in Google Analytics that allowed protected health information (PHI) to be shared with Google Ads between April 2021 and January 2024. The issue was discovered on February 11, 2025. Affected data includes insurance plan details, medical claim service dates, provider names, and patient financial responsibility. No malicious actor was involved; the exposure resulted from a vendor configuration error. Blue Shield severed the connection and reviewed security protocols.
- 🐻California State AGas victim2025-03-28
Blue Shield of California notified members that a data mismatch error in a health information exchange feed allowed family members on the same plan to potentially view each other's health records (visit types, dates, providers, medications) via the Member Portal between Oct 28 and Nov 11, 2024. The issue was identified on Nov 8, 2024, and the data feed was terminated on Nov 11, 2024. No demographic identifiers, SSNs, or financial data were exposed.
- CALIFORNIAHHS OCRas victim2025-02-28
Blue Shield of California reported to HHS on 2025-02-28 an Unauthorized Access/Disclosure affecting 624 individuals. Due to a configuration error, PHI including medications and other treatment information was viewable by others via the Internet through an Electronic Medical Record system. The CE notified HHS, affected individuals, and the media, and provided free credit monitoring.
- 🐻California State AGas victim2024-01-04
Welltok, Inc., a third-party service provider for Blue Shield of California, disclosed that an unknown actor exploited software vulnerabilities in its MOVEit Transfer server on May 30, 2023, exfiltrating data including names and other personal information. Welltok was alerted to the compromise on July 26, 2023. The incident affects Blue Shield members. Welltok is offering credit monitoring services.
- CALIFORNIAHHS OCRas victim2023-11-17
Blue Shield of California OR Blue Shield of California Promise Health Plan reported to HHS on 2023-11-17 a Hacking/IT Incident affecting 27,832 individuals. Breached information located on Network Server. The covered entity's business associate experienced a cyber-attack compromising PHI including names, SSNs, diagnoses, addresses, birthdates, and claims. The CE provided complimentary credit monitoring and implemented additional safeguards.
- CALIFORNIAHHS OCRas victim2023-04-05
California Physicians' Services dba Blue Shield of California reported to HHS on 2023-04-05 a Hacking/IT Incident affecting 1,553 individuals. The breach occurred at a subcontractor of the covered entity's business associate, impacting PHI stored on a network server. PHI exposed included names, dates of birth, and addresses. The CE severed connections to affected servers, implemented additional technical safeguards, and offered credit monitoring to affected individuals.
- CALIFORNIAHHS OCRas victim2023-04-04
California Physicians' Services d/b/a Blue Shield of California reported to HHS on 2023-04-04 a Hacking/IT Incident affecting 61,788 individuals. Breached information located on Network Server. The incident involved a business associate's subcontractor. PHI included names, dates of birth, and addresses.
- 🐻California State AGas victim2023-03-31
Blue Shield of California notified members that a third-party subcontractor, Fortra, LLC, suffered a cybersecurity incident between January 28-31, 2023. An unauthorized individual accessed Fortra's GoAnywhere MFTaaS application and potentially exfiltrated files maintained by Blue Shield's provider, Brightline Medical Associates. Affected data included names, addresses, dates of birth, gender, subscriber IDs, phone numbers, emails, and plan information. No SSNs or financial data were accessed. Blue Shield locked communications with Brightline and offered one year of Experian IdentityWorks.
- 🦞Maine State AGas victim2023-03-27
Blue Shield of California, acting as a business associate, experienced an external system breach (hacking) from January 28, 2023, to January 31, 2023. The incident was discovered on January 30, 2023. The breach affected 44 Maine residents, who were notified via written communication on March 27, 2023. The company offered one year of complimentary credit monitoring and identity theft restoration services to those affected.
- 🦞Maine State AGas victim2022-12-29
California Physicians' Services d/b/a Blue Shield of California (BSC) reported an insider wrongdoing incident occurring between June 17, 2022, and October 30, 2022. The breach compromised names and Social Security Numbers of 3,411 individuals, including one Maine resident. BSC notified affected individuals in writing on December 22, 2022, and offered one year of credit monitoring through Experian IdentityWorks.
- 🐻California State AGas victim2022-07-12
Blue Shield of California notified members of a ransomware attack on OneTouchPoint (OTP), a subcontractor of vendor Matrix Medical Network. OTP detected suspicious network activity on April 28, 2022; Blue Shield learned of the incident on May 20, 2022. Affected members' PHI may have included names, subscriber IDs, diagnoses, medications, addresses, and other health data. No SSNs, driver's licenses, or financial data were accessed. One year of Experian IdentityWorks was offered.
- 🐻California State AGas victim2021-12-13
Blue Shield of California notified members of a ransomware attack on third-party broker OneDigital on January 20, 2021. Blue Shield learned of the incident on October 4, 2021. Although no evidence of access to Blue Shield systems was found, member PHI (name, DOB, subscriber ID) may have been accessed. Blue Shield offered one year of Experian IdentityWorks.
- CALIFORNIAHHS OCRas victim2021-11-19
Blue Shield of California reported to HHS on 2021-11-19 a Hacking/IT Incident affecting 1519 individuals. A business associate experienced a ransomware attack compromising PHI (names, DOB, SSN) located on a network server. The CE provided credit monitoring and implemented safeguards.
- CALIFORNIAHHS OCRas victim2021-10-27
California Physicians' Services dba Blue Shield of California (Health Plan, CA) reported to HHS on 2021-10-27 that its business associate experienced a ransomware attack compromising the ePHI of 2,841 individuals. Breached information was located on a Network Server and included names, addresses, dates of birth, and health insurance information. The BA notified law enforcement; the CE notified HHS, affected individuals, and the media, and provided substitute notice.
- 🐻California State AGas victim2021-10-27
Blue Shield of California notified members of a ransomware attack on August 25, 2021 targeting Team Alvarez, a Blue Shield broker. The unauthorized access was terminated the same day. Potentially exposed PHI included names, addresses, phone numbers, email addresses, dates of birth, gender, subscriber ID numbers, policy effective dates, emergency contact information, and broker information. No SSNs, driver's license numbers, or financial account data were accessed. Blue Shield offered one year of complimentary Experian IdentityWorks to affected members.
- 🐻California State AGas victim2020-11-06
Blue Shield of California experienced a data incident in October 2020 where provider directories incorrectly displayed members' Social Security Numbers or Tax Identification Numbers as provider IDs. The error occurred on Blue Shield's and vendor Arvato's websites between October 16-20, 2020. Blue Shield removed the directories, retrieved/destroyed copies, and offered 12 months of Experian IdentityWorks. No misuse is known.
- 🐻California State AGas victim2019-02-15
California Physicians' Service d/b/a Blue Shield of California disclosed a data breach involving third-party vendor Sharecare Health Data Services. Between May 21 and June 26, 2018, an unknown third party accessed Sharecare servers containing member data, including names, addresses, DOBs, and SSNs (for a subset). Blue Shield notified members on February 15, 2019, offering credit monitoring. The incident involved unauthorized access and data exfiltration to locations outside the US.