Did Kaiser Foundation Health Plan have a data breach?
Answer
Yes. Kaiser Foundation Health Plan reported a data breach to the CA Attorney General on March 12, 2026. The filing lists about 13,400,000 people affected.
What the filing says
- Reported to
- California Attorney General
- Filing date
- March 12, 2026
- Breach date
- April 12, 2024
- People affected
- 13,400,000
- Type of incident
- Unauthorized Disclosure
Information involved
- member names
- IP addresses
- health-related web activity
In plain terms
Kaiser Foundation Health Plan in California reported an unauthorized disclosure affecting 13.4 million individuals. Online tracking technologies transmitted member names, IP addresses, and health-related web activity to third-party vendors.
Kaiser Foundation Health Plan has filed a data breach report with the California Attorney General, indicating an unauthorized disclosure affecting approximately 13,400,000 individuals. The incident occurred on April 12, 2024, and was officially reported on March 12, 2026.
According to the official filing, the breach stemmed from the use of online tracking technologies. These tools inadvertently transmitted certain member information to third-party vendors without proper authorization.
The specific categories of data identified as exposed include member names, IP addresses, and health-related web activity. These details are based directly on the information provided in the public breach filing.
Individuals potentially affected by this disclosure should remain vigilant about their online privacy. It is advisable to review privacy settings on all accounts and be cautious of unsolicited communications, as a general protective measure.
The investigation into this incident is currently ongoing, with authorities continuing to monitor the situation. This information reflects details available from the official regulatory filing.
Commonly recommended next steps
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in CA
- American Addiction CentersYes — reportedCA · August 7, 2026
- Cushman & WakefieldYes — reportedCA · August 7, 2026
- Hamill & KaplanYes — reportedCA · August 6, 2026
- New York City Regional Center, LLCYes — reportedCA · August 5, 2026
- UCLA HealthYes — reportedCA · August 4, 2026
- BAYADA Home Health Care, Inc.Yes — reportedCA · July 17, 2026
- The Estée Lauder CompaniesYes — reportedCA · July 17, 2026
- ZenPatient, Inc.Yes — reportedCA · July 17, 2026
- Quontic Bank Acquisition Corp.Yes — reportedCA · July 17, 2026
- DentaQuest LLCYes — reportedCA · July 16, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Kaiser Foundation Health Plan.