Blue Shield of California disclosed an unauthorized disclosure of Protected Health Information (PHI) resulting from a website code update on May 9, 2015. A vulnerability allowed authorized users to view another user's PHI, including names, SSNs, and dates of birth, between May 9 and May 18, 2015. The website was taken offline, the code was fixed, and affected individuals were offered one year of credit monitoring.