- State
- CA
- Covered entity type
- Health Plan
- Individuals affected
- 609
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On September 8, 2017, the covered entity (CE), Kaiser Foundation Health Plan, discovered that a physician at its Riverside Medical Center scanned his daily schedule for dates of service between August 2014 to August 2017, which contained patient information including names, medical record numbers, and procedure types for 609 patients. The physician inadvertently e-mailed the information to an external gmail account that does not belong to the physician. Following the breach, the CE re-programed the device that was used to scan/email the document at issue so that it is no longer possible for an email to leave the CE's information technology network from the device. The CE provided notification to HHS, affected individuals, and the media pursuant to the Breach Notification Rule. Following the breach, the CE retrained the physician who mis-sent the PHI at issue in this breach. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.