Calif. Dept. of Health Care Services
Disclosed Dec 23, 201213 years ago2,643 affectedConfirmed
The covered entity (CE), California Department of Health Care Services reported that 2,705 member identification cards were mailed to the wrong households. Due to a computer programming error in the electronic file for multiple beneficiaries living in the same household, some cards for these beneficiaries were sent to the wrong households. The types of protected health information (PHI) on the cards included names, dates of birth, genders, dates of issue, and Medi-Cal-assigned numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE put an immediate hold on additional mailings and conducted a quality assurance check. The CE deactivated the cards that were mailed to the wrong addresses, requested the return of the deactivated cards, and issued replacements. The CE implemented a new internal data transfer policy and updated related procedures. It also instituted new processes for mailings. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 2,643 (as reported to HHS) |
|---|---|
| Disclosed | Dec 23, 2012 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Calif. Dept. of Health Care Services (Health Plan, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 23, 2012 | 2,643 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.