Skip to content

CCPOA Benefit Trust Fund

Disclosed Oct 29, 20205 years ago80,000 affectedConfirmed

Official notice

The covered entity (CE), CCPOA Benefit Trust Fund, reported that it was the victim of a ransomware attack that affected the electronic protected health information (ePHI) of 80,000 individuals. The ePHI involved included names, addresses, Social Security numbers, and phone numbers. The CE notified HHS, affected individuals, and the media. The CE also provided complimentary credit monitoring services. As a result of OCR’s investigation, the CE revised its HIPAA security procedures, retrained its workforce members, and implemented additional technical safeguards to better protect its systems that maintain ePHI.

What is known

People affected80,000 (as reported to HHS)
DisclosedOct 29, 2020
HappenedSep 2, 2020
AttackHacking
Data exposedNames, Health
SectorFinance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: CCPOA Benefit Trust Fundoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): CCPOA Benefit Trust Fund (Health Plan, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAOct 29, 2020
HHS archivetotalOct 29, 202080,000
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 80000 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), CCPOA Benefit Trust Fund, reported that it was the victim of a ransomware attack that affected the electronic protected health information (ePHI) of 80,000 individuals. The ePHI involved included names, addresses, S · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about CCPOA Benefit Trust Fund

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.