- State
- OR
- Covered entity type
- Health Plan
- Individuals affected
- 544
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 12, 2016, Kaiser Permanente upgraded its website, kp.org, which resulted in an incorrect configuration setting for caching data. This website upgrade affected several covered entities (CEs), including the Kaiser Foundation Health Plan of the Northwest. As a result of the error, some users who logged into the website may have had some of the protected health information (PHI) they viewed online saved into the cache where it could be seen by other visitors to the webpage. Kaiser Permanente was alerted to the incident and took action to repair the error. The breach affected approximately 544 individuals participating with this CE. The types of PHI involved in the breach included clinical and demographical information. The CE provided individual and substitute breach notifications. In response to the breach, the CE created a corrective action plan to help mitigate the chances of a misconfiguration error by educating the relevant IT staff, creating new processes, ensuring sign offs and approvals at appropriate points in the process, testing an outcome before going live, and engaged a subject matter expert. OCR provided the CE with technical assistance regarding the HIPAA Security Rule including risk analysis and risk management.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.