Confirmed breach. Intrusion Aug 9, 2017–Sep 18, 2017, discovered Aug 9, 2017 — the first regulatory filing landed 22 days later. 720 individuals reported across the linked filings.
On August 9, 2017, Kaiser Foundation Health Plan inadvertently emailed a document containing protected health information (name, medical record number, procedure, and date of service) to an unknown external email address. The incident was classified as an inadvertent error with no evidence of hacking or bad intent. Notification was sent on August 30, 2017.
CA 60-day OK · 21d
Breach discoveredconflicts with Aug 9, 2017letter-grounded
Sep 21, 2017
Reported by CALIFORNIA AG filing
🐻CALIFORNIAHHS OCRlinked via same-victim cross-source · 100%
Kaiser Foundation Health Plan reported to HHS on 2017-10-20 a Unauthorized Access/Disclosure affecting 720 individuals. Breached information located on Paper/Films. A business associate superimposed patient addresses during a batch mailing of outreach letters, resulting in 720 patients receiving letters intended for others. Demographic information (names and addresses) was exposed. Corrective actions included implementing secondary Quality Assurance checks and adding a CE manager for final sign-off.
Kaiser Foundation Health Plan, Inc. notified members that a letter intended for one member was inadvertently mailed to another. The letter referenced the Liver Care Program and contained the member's first and last name and medical record number. No financial data or other medical information was involved. The organization is reviewing internal processes to prevent recurrence.
CA 60-day OK · 19d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.