CalOptima (CA Health Plan) reported to HHS on 2016-08-22 an Unauthorized Access/Disclosure affecting approximately 15,800 individuals (HHS portal shows 1,000 threshold entry). A departing employee impermissibly copied PHI — including names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment info, Medicaid beneficiary numbers, and SSNs — to an unauthorized USB device on her final days of employment. The breach was detected via CalOptima's data loss prevention system. The CE notified affected individuals, media, and HHS, reported to law enforcement, and implemented corrective actions including disabling USB write privileges for all employees.
Affected (this filing): 1,000