Kaiser Foundation Healthplan, Inc. of Southern California
Disclosed Nov 6, 20169 years ago3,044 affectedConfirmed
The covered entity (CE), Kaiser Permanente (KP), reported that an error in its website configuration setting allowed some users to view the protected health information (PHI) of others. The breach affected approximately 3,044 individuals. The types of PHI involved included names, addresses, dates of birth, claims information, clinical information, financial information, medications prescribed, and other treatment information. In response to the breach, KP created a corrective action plan to help mitigate the chances of a misconfiguration error and retrained its staff. It also implemented additional administrative, technical and security safeguards. OCR provided KP with technical guidance regarding the Security Rule including risk analysis and risk management processes and procedures.
What is known
| People affected | 3,044 (as reported to HHS) |
|---|---|
| Disclosed | Nov 6, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Kaiser Foundation Healthplan, Inc. of Southern California (Health Plan, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 6, 2016 | 3,044 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Kaiser Foundation Healthplan, Inc. of Southern California