Skip to content

CalOptima

Disclosed Aug 22, 201610 years ago1,000 affectedConfirmed

Official notice

An employee of CalOptima, the covered entity (CE), impermissibly copied data files containing the protected health information (PHI) of patients to an unauthorized electronic mobile storage device (a universal serial bus (USB)) on her last days of employment with the CE. The CE discovered the breach through its data loss prevention system. The breach affected approximately 15,800 individuals. The types of PHI involved included full names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment information, Medicaid beneficiary numbers, and social security numbers. The CE provided breach notification to affected individuals, the media, and HHS, and also provided substitute notice. Following the breach, the CE immediately reported the incident to local law enforcement. As a result of the incident, the CE updated its policies and procedures, disabled USB device write privileges for all employees, and made sure its information security team will be informed when employees separated from the CE. The CE also implemented a new procedure requiring employees to justify and receive approval from management before submitting a request to its information sec

What is known

People affected1,000 (as reported to HHS)
DisclosedAug 22, 2016
HappenedAug 17, 2016
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: CalOptimaoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): CalOptima (Health Plan, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 22, 20161,000
California AGresidents of CAOct 14, 2016

Other breaches at CalOptima

BreachAffected
Disclosed Oct 27, 2021Oct 27, 20214 years agoUnknown
History of this record
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 1000 · backfill source
  • 2026-09-25 · disclosed: 2016-10-14 to 2016-08-22 · backfill source
  • 2026-09-25 · summary: empty to An employee of CalOptima, the covered entity (CE), impermissibly copied data files containing the protected health information (PHI) of patients to an unauthorized electronic mobile storage device (a universal serial bus (USB)) on her last · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about CalOptima

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.