Skip to content

Blue Shield of California

Disclosed Jan 14, 201610 years ago20,764 affectedConfirmed

Official notice

On December 7, 2015, Blue Shield of California, the covered entity (CE), discovered that its servers were breached via social engineering at its call centers in Costa Rica. The breach affected 20,764 patients’ protected health information (PHI). The types of PHI involved included patients’ names, addresses, dates of births, and social security numbers. The CE provided breach notification to HHS, affected individuals, the media. In response to the breach, the CE disabled all existing login credentials and manually distributed new passwords. It trained all call center workforce members about the risks of social engineering and implemented two-factor authentication for external access to its network via its virtual private network (VPN). The CE also provided OCR with additional documentation as relevant to the breach investigation, including its HIPAA Notice of Privacy Practices Policy. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected20,764 (as reported to HHS)
DisclosedJan 14, 2016
HappenedSep 15, 2015
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Blue Shield of Californiaoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): Blue Shield of California (Health Plan, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAJan 14, 2016
HHS archivetotalJan 14, 201620,764

Other breaches at Blue Shield of California

BreachAffected
Google Analytics misconfiguration shared 4.7M members' health dataFeb 28, 20251 year agoExposed data4.7M
Disclosed Jul 12, 2022Jul 12, 20224 years agoHacking1,506
Disclosed Oct 27, 2021Oct 27, 20214 years agoHacking1,519
Disclosed Feb 18, 2014Feb 18, 201412 years agoUnknown
History of this record
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 20764 · backfill source
  • 2026-09-25 · summary: empty to On December 7, 2015, Blue Shield of California, the covered entity (CE), discovered that its servers were breached via social engineering at its call centers in Costa Rica. The breach affected 20,764 patients’ protected health information ( · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Blue Shield of California

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.