On October 5, 2018, the covered entity (CE), Gold Coast Health Plan, reported that phishing attacks compromised its workforce members’ emails, affecting 37,005 individuals. The types of protected health information (PHI) involved in the breach included names, dates of birth, Medi-Cal numbers, health plan names, claims information, diagnoses/conditions, and other treatment information. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE implemented new technical safeguards, trained its workforce members on phishing attacks, and implemented risk analysis and risk management plans as recommended by its security company. The CE also provided OCR with additional documentation including its revised policies and procedures and its new employee orientation packet relevant to this breach investigation. OCR obtained assurances that the CE implemented the corrective actions listed above. .
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 37005 · backfill source
2026-09-25 · summary: empty to On October 5, 2018, the covered entity (CE), Gold Coast Health Plan, reported that phishing attacks compromised its workforce members’ emails, affecting 37,005 individuals. The types of protected health information (PHI) involved in the bre · backfill source