Court Rules
All enforcement actions
Enforcement ActionLow Risk

CA AG Alleges Kaiser Improperly Disposed of Patient Medical Records

Kaiser Foundation Health Plan, Inc.January 23, 2014California Attorney General

Summary

The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.

Contract Impact

In-house legal teams should review all agreements involving the handling of protected health information (PHI), particularly vendor contracts with waste management/recycling services, business associate agreements (BAAs) with third-party processors, and employee confidentiality agreements. Key clauses to scrutinize include data disposal and destruction protocols, confidentiality terms specific to medical records, breach notification requirements, audit rights for compliance verification, and retention schedules. Changes may be needed to mandate certified disposal methods (e.g., cross-shredding), require immediate reporting of unauthorized disposal incidents, incorporate regular training obligations for vendors, and strengthen indemnification provisions for privacy violations under state medical confidentiality laws.

Contract Search Terms

data disposal proceduresprotected health information handlingbusiness associate agreementbreach notification clausemedical records retention scheduleconfidentiality of medical informationvendor data security requirementsPHI access controlsshredding protocolsrecycling facility agreement

Laws Cited

California Confidentiality of Medical Information ActCal. Civ. Code 56 et seq.
Cal. Civ. Code 56 et seq.

Violation Types

Entity Details

Entity

Kaiser Foundation Health Plan, Inc.

Also known as: Kaiser

Industry

Healthcare

Official Sources

Related Enforcement Actions

HHS

Kaiser Foundation Health Plan, Inc.

Kaiser Foundation Health Plan, Inc. (Health Plan, CA) reported a HIPAA breach affecting 13,400,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.