Skip to content

Blue Cross of California

Disclosed Oct 26, 20214 years ago672 affectedConfirmed

Official notice

The covered entity (CE), Blue Cross of California, reported that its business associate (BA) experienced a ransomware attack that affected the electronic protected health information (ePHI) of 672 individuals. The ePHI involved included names, gender, email addresses, phone numbers, home addresses, Social Security numbers, health insurance information, and other treatment information.

What is known

People affected672 (as reported to HHS)
DisclosedOct 26, 2021
HappenedAug 25, 2021
AttackHacking
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Blue Cross of Californiaoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): Blue Cross of California (Health Plan, IN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAOct 26, 2021
HHS archivetotalOct 27, 2021672
History of this record
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 672 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Blue Cross of California, reported that its business associate (BA) experienced a ransomware attack that affected the electronic protected health information (ePHI) of 672 individuals. The ePHI involved included nam · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Blue Cross of California

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.