An employee of CalOptima, the covered entity (CE), impermissibly copied data files containing the protected health information (PHI) of patients to an unauthorized electronic mobile storage device (a universal serial bus (USB)) on her last days of employment with the CE. The CE discovered the breach through its data loss prevention system. The breach affected approximately 15,800 individuals. The types of PHI involved included full names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment information, Medicaid beneficiary numbers, and social security numbers. The CE provided breach notification to affected individuals, the media, and HHS, and also provided substitute notice. Following the breach, the CE immediately reported the incident to local law enforcement. As a result of the incident, the CE updated its policies and procedures, disabled USB device write privileges for all employees, and made sure its information security team will be informed when employees separated from the CE. The CE also implemented a new procedure requiring employees to justify and receive approval from management before submitting a request to its information sec
2026-09-25 · sector: other to insurance · backfill source
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 1000 · backfill source
2026-09-25 · disclosed: 2016-10-14 to 2016-08-22 · backfill source
2026-09-25 · summary: empty to An employee of CalOptima, the covered entity (CE), impermissibly copied data files containing the protected health information (PHI) of patients to an unauthorized electronic mobile storage device (a universal serial bus (USB)) on her last · backfill source