KP Northern CA Department of Research
Disclosed Apr 2, 201412 years ago5,178 affectedConfirmed
The covered entity (CE), Kaiser Permanente Northern California Division of Research, reported a breach of 5,178 individuals’ electronic protected health information (e-PHI), as a result of a malware software infection on its computer server. The types of ePHI involved in the breach included names, dates of birth, genders, addresses, race/ethnicity information, medical record numbers, lab results, and responses patients provided to research-related questions. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE conducted an updated security analysis, revised its policies and procedures, and provided training to its workforce members. OCR obtained written assurances that the CE implemented the corrective actions noted above and provided technical assistance regarding the HIPAA Security Rule.
What is known
| People affected | 5,178 (as reported to HHS) |
|---|---|
| Disclosed | Apr 2, 2014 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): KP Northern CA Department of Research (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 2, 2014 | 5,178 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.