Skip to content

Kaiser Permanente

Disclosed Sep 26, 20197 years ago990 affectedConfirmed

Official notice

The covered entity (CE), Kaiser Permanente in Oakland, California, reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information of 990 individuals. The ePHI involved included names, birthdates, gender, diagnoses, health insurance information, clinical information, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI. OCR provided technical assistance to the CE regarding the HIPAA Security Rule.

What is known

People affected990 (as reported to HHS)
DisclosedSep 26, 2019
HappenedAug 12, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Kaiser Permanenteoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): Kaiser Permanente (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CASep 26, 2019
HHS archivetotalSep 26, 2019990

Other breaches at Kaiser Permanente

BreachAffected
Tracking code on Kaiser websites and apps shared data of 13.4 million membersApr 25, 20242 years agoExposed dataUnverified13M
Disclosed Apr 16, 2012Apr 16, 201214 years agoUnknown
Stolen laptop held names and member numbers of 160,000 Kaiser membersJul 27, 200620 years agoLost or stolen deviceUnverified160K
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 990 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Kaiser Permanente in Oakland, California, reported that an employee was the victim of an email phishing scheme that affected the electronic protected health information of 990 individuals. The ePHI involved included · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Kaiser Permanente

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.