- State
- CA
- Covered entity type
- Health Plan
- Individuals affected
- 2,643
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), California Department of Health Care Services reported that 2,705 member identification cards were mailed to the wrong households. Due to a computer programming error in the electronic file for multiple beneficiaries living in the same household, some cards for these beneficiaries were sent to the wrong households. The types of protected health information (PHI) on the cards included names, dates of birth, genders, dates of issue, and Medi-Cal-assigned numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE put an immediate hold on additional mailings and conducted a quality assurance check. The CE deactivated the cards that were mailed to the wrong addresses, requested the return of the deactivated cards, and issued replacements. The CE implemented a new internal data transfer policy and updated related procedures. It also instituted new processes for mailings. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.