Back to the register

Kaiser Foundation Health Plan

ArchivedSubmitted 09/08/2017
State
CA
Covered entity type
Health Plan
Individuals affected
609
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On September 8, 2017, the covered entity (CE), Kaiser Foundation Health Plan, discovered that a physician at its Riverside Medical Center scanned his daily schedule for dates of service between August 2014 to August 2017, which contained patient information including names, medical record numbers, and procedure types for 609 patients. The physician inadvertently e-mailed the information to an external gmail account that does not belong to the physician. Following the breach, the CE re-programed the device that was used to scan/email the document at issue so that it is no longer possible for an email to leave the CE's information technology network from the device. The CE provided notification to HHS, affected individuals, and the media pursuant to the Breach Notification Rule. Following the breach, the CE retrained the physician who mis-sent the PHI at issue in this breach. OCR obtained assurances that the CE implemented the corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.