- State
- CA
- Covered entity type
- Health Plan
- Individuals affected
- 1,000
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of CalOptima, the covered entity (CE), impermissibly copied data files containing the protected health information (PHI) of patients to an unauthorized electronic mobile storage device (a universal serial bus (USB)) on her last days of employment with the CE. The CE discovered the breach through its data loss prevention system. The breach affected approximately 15,800 individuals. The types of PHI involved included full names, addresses, dates of birth, claims information, diagnosis/conditions, medications, treatment information, Medicaid beneficiary numbers, and social security numbers. The CE provided breach notification to affected individuals, the media, and HHS, and also provided substitute notice. Following the breach, the CE immediately reported the incident to local law enforcement. As a result of the incident, the CE updated its policies and procedures, disabled USB device write privileges for all employees, and made sure its information security team will be informed when employees separated from the CE. The CE also implemented a new procedure requiring employees to justify and receive approval from management before submitting a request to its information security team to receive permission to write to USB devices. OCR obtained assurances from the CE that it implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.