Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kaiser Permanente

Kaiser Permanente Vendor Cyber Rating & Cyber Score

kp.org

At the heart of health care, you’ll find Kaiser Permanente. As the nation’s leading not-for-profit, integrated health plan, we make a difference in the lives of members, patients, and communities across the country. With 39 hospitals and more than 734 locations in eight states and the District of Columbia, we proudly serve more than 12.7 million members from coast to coast. Whether you choose to join a hospital in the Northwest, a clinic in Southern California, or a medical office in the Mid-Atlantic, we have many opportunities for you to shape the future of care. Our teams are empowered to advance impactful and extraordinary care for all by pioneering health outcomes, encouraging diverse viewpoints, and creating new opportunities for


Kaiser Permanente A.I CyberSecurity Scoring

Kaiser Permanente
Company Information
Website:http://kp.org
Employees number:133,680
Number of followers:1,049,900
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:kp.org
Kaiser Permanente Risk Score (AI oriented)
Between 0 and 549
logo
Kaiser PermanenteHospitals and Health Care
Updated:
04/04/2026
194/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kaiser Permanente Global Score (TPRM)
xxxx
logo
Kaiser PermanenteHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kaiser Permanente
Kaiser PermanenteCritical
Current Score
194C (CRITICAL)
01000
17 incidents
-143 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
213Before Incident
MAY 2026
212Before Incident
APRIL 2026
206Before Incident
MARCH 2026
188Before Incident
FEBRUARY 2026
186Before Incident
JANUARY 2026
316Before Incident
Breach
12 Jan 2026Kaiser Permanente
Kaiser Permanente: Kaiser Permanente to pay $46 million in privacy data breach settlement. Here’s how to file a claim.

Kaiser Permanente Patient Data Breach Settlement

173After Incident
CRITICAL-143
KAI1768267117
Kaiser Permanente Settles $46M Lawsuit Over Patient Data Exposure via Tracking Tools Kaiser Permanente has agreed to a $46 million settlement to resolve a class-action lawsuit alleging unauthorized sharing of patient data through third-party tracking tools on its websites and mobile apps. The settlement, preliminarily approved in December 2025, covers approximately 13 million current and former members across nine states and the District of Columbia. The lawsuit, consolidated from multiple filings in 2024, claimed that from November 2017 to May 2024, Kaiser’s digital platforms transmitted sensitive information including IP addresses, names, medical histories, and user navigation details to companies like Google, Microsoft, Meta, and Twitter/X without explicit consent. Kaiser denied any misuse of data or exposure of Social Security numbers or financial information but opted to settle to avoid prolonged litigation. Eligible members, who accessed Kaiser’s websites or apps during the affected period, may receive a one-time payment of $20 to $40 from the settlement fund, which could increase to $47.5 million. Claims must be filed by March 12, 2026, via the settlement website, with payments distributed after final court approval on May 7, 2026. Payouts will be issued electronically or by check. Kaiser stated it removed the tracking technologies in 2024 and implemented additional safeguards to prevent future incidents. The company maintains no evidence of data misuse but emphasized the settlement as a resolution to legal uncertainty.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $46 million (settlement fund)Data Compromised: Confidential personal and health information, including IP addresses, names, search terms, medical histories, communications with healthcare professionals, and navigation detailsSystems Affected: Kaiser Permanente websites and mobile applicationsOperational Impact: Removal of certain online technologies and implementation of additional safeguardsBrand Reputation Impact: Potential reputational damage due to alleged data breachLegal Liabilities: Class-action lawsuit settlementIdentity Theft Risk: Potential risk due to exposure of personal and health information
DATA BREACH
Personal informationHealth informationSensitivity Of Data: High (medical histories, communications with healthcare professionals)Data Exfiltration: Transmitted to third parties (Google, Microsoft, Meta, Twitter/X)IP addressesNamesSearch termsMedical historiesNavigation details
DECEMBER 2025
344Before Incident
NOVEMBER 2025
304Before Incident
OCTOBER 2025
295Before Incident
SEPTEMBER 2025
286Before Incident
AUGUST 2025
277Before Incident
JULY 2025
268Before Incident
AUGUST 2024
200Before Incident
Breach
02 Aug 2024Kaiser Permanente
Kaiser Foundation Hospitals

Kaiser Foundation Hospitals Data Breach

142After Incident
HIGH-58
KAI603072625
The California Office of the Attorney General reported that Kaiser Foundation Hospitals experienced a data breach on August 2, 2024, which was discovered on September 3, 2024. Unauthorized access occurred to the email accounts of two workforce members, potentially exposing protected health information of individuals. The number of individuals affected is not specified.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Protected Health InformationSystems Affected: Email Accounts
DATA BREACH
Type Of Data Compromised: Protected Health InformationSensitivity Of Data: High
JUNE 2024
290Before Incident
Breach
16 Jun 2024Kaiser Permanente
Kaiser Permanente

Kaiser Permanente Data Breach

184After Incident
CRITICAL-106
KAI004032225
Kaiser Permanente, a leading healthcare organization, has reported a significant data breach affecting 13.4 million members, marking it as the largest healthcare-related data breach of 2024. The compromised information includes names, IP addresses, account interaction details, and navigational data on Kaiser's websites and mobile apps. The breach resulted from tracking code that shared data with third-party advertisers, including major tech companies like Google, Microsoft, and X (formerly Twitter). This incident has raised privacy concerns and prompted Kaiser to remove the tracking code and notify the affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesIP addressesAccount interaction detailsNavigational dataWebsitesMobile apps
DATA BREACH
NamesIP addressesAccount interaction detailsNavigational dataNumber Of Records Exposed: 13.4 millionNamesIP addresses
MAY 2024
473Before Incident
Breach
01 May 2024Kaiser Permanente
Kaiser Permanente: Kaiser Permanente to pay $46 million in privacy data breach settlement. Here's how to file a claim.

Kaiser Permanente Patient Data Breach Settlement

330After Incident
CRITICAL-143
KAI1768267006
Kaiser Permanente Settles $46M Lawsuit Over Alleged Patient Data Breaches Kaiser Permanente has agreed to a $46 million settlement to resolve a class-action lawsuit alleging unauthorized sharing of patient data through its websites and mobile apps. The settlement, preliminarily approved in December 2025, stems from multiple lawsuits filed in 2024, which were consolidated into a single case. The lawsuit claimed that from November 2017 to May 2024, Kaiser’s digital platforms used third-party tracking tools including code from Google, Microsoft, Meta, and Twitter/X that transmitted sensitive information without user consent. Exposed data reportedly included IP addresses, names, medical histories, search terms, and user navigation details. Kaiser denied any misuse of data or exposure of Social Security numbers or financial information, stating the settlement was reached to avoid prolonged litigation. Eligible members current or former Kaiser patients in nine states and D.C. who accessed its websites or apps during the affected period may receive a one-time payment of $20 to $40 from the settlement fund, which could increase to $47.5 million. Claims must be filed by March 12, 2026, via the settlement website, with payments distributed after final court approval on May 7, 2026. Payouts will be issued electronically or by check. Kaiser stated it removed the tracking technologies in 2024 and implemented additional safeguards to prevent future incidents. The company maintains no evidence of data misuse but settled to resolve the legal dispute.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $46 million (settlement fund)Data Compromised: Confidential personal and health information, including IP addresses, names, search terms, medical histories, communications with healthcare professionals, and site navigation detailsWebsitesMobile applicationsOperational Impact: Removal of certain online technologies and implementation of additional safeguardsBrand Reputation Impact: Potential reputational damage due to alleged data breachLegal Liabilities: Class-action lawsuit settlementPayment Information Risk: Denied exposure of financial information
DATA BREACH
Personal informationHealth informationSensitivity Of Data: High (medical histories, communications with healthcare professionals)Data Exfiltration: Transmitted to third parties (Google, Microsoft, Meta, Twitter/X)IP addressesNamesSearch termsMedical historiesSite navigation details
OCTOBER 2023
436Before Incident
Breach
25 Oct 2023Kaiser Permanente
Kaiser Foundation Health Plan, Inc.

Data Breach at Kaiser Foundation Health Plan, Inc.

378After Incident
LOW-58
KAI842072625
The California Office of the Attorney General reported a data breach involving Kaiser Foundation Health Plan, Inc. on April 12, 2024. The incident occurred on October 25, 2023, when certain online technologies potentially transmitted personal information such as IP addresses and names to third-party vendors. Detailed information like Social Security numbers and financial information was not involved.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
IP addressesnames
DATA BREACH
IP addressesnamesSensitivity Of Data: LowIP addressesnames
SEPTEMBER 2022
414Before Incident
Data Leak
01 Sep 2022Kaiser Permanente
Kaiser Permanente

Improper Access to Health Information at Kaiser Foundation Health Plan of the Mid-Atlantic States

340After Incident
CRITICAL-74
KAI184191222
Kaiser Foundation Health Plan of the Mid-Atlantic States notified 8,556 individuals of improper access to their health information. In September 2022, Kaiser Permanente determined that an employee had inappropriately accessed medical records without a legitimate reason for doing so. The employee viewed a variety of information, including names, medical record numbers, phone numbers, birth dates, addresses, medical information, and photographs.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Unauthorized Access
IMPACT
NamesMedical Record NumbersPhone NumbersBirth DatesAddressesMedical InformationPhotographs
DATA BREACH
NamesMedical Record NumbersPhone NumbersBirth DatesAddressesMedical InformationPhotographsSensitivity Of Data: HighNamesMedical Record NumbersPhone NumbersBirth DatesAddressesPhotographs
MAY 2022
449Before Incident
Breach
20 May 2022Kaiser Permanente
Kaiser Foundation Health Plan, Inc.

Kaiser Permanente Data Breach

391After Incident
HIGH-58
KAI703072925
The California Office of the Attorney General reported on July 15, 2022, that Kaiser Permanente experienced a data breach on May 20, 2022, involving the theft of an iPad from a medical center. The breach potentially affected individuals' first names, last names, medical record numbers, dates of birth, and service dates. The breach response included notifying law enforcement and remotely erasing the iPad's data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
first nameslast namesmedical record numbersdates of birthservice dates
DATA BREACH
Personally Identifiable InformationSensitivity Of Data: High
APRIL 2022
519Before Incident
Breach
01 Apr 2022Kaiser Permanente
Kaiser Permanente

Unauthorized Access to Kaiser Permanente's Email System

440After Incident
CRITICAL-79
KAI12717622
Unauthorized access to the US healthcare giant Kaiser Permanente's email system exposed the healthcare and personal information of up to 70,000 patients. The breach exposed patients’ first and last names, medical record numbers, dates of service, and laboratory test result information of the health plan provider. Kaiser Permanente asked all of its employees to reset their passwords for their email accounts and arranged additional training on safe email practices for all its staff.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
first and last namesmedical record numbersdates of servicelaboratory test result informationemail system
DATA BREACH
Healthcare InformationPersonal Informationfirst and last namesmedical record numbersdates of servicelaboratory test result information
SEPTEMBER 2021
582Before Incident
Ransomware
01 Sep 2021Kaiser Permanente
TTEC

Ransomware Attack on TTEC

486After Incident
CRITICAL-96
TTE16021322
The systems of TTEC were affected by ransomware attack by the Ragnar Locker group on its servers. The outage impacted the access to the network, applications and customer support. The attackers gained the access to the systems and left messages on its syetmes asking for ransom.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial
IMPACT
NetworkApplicationsCustomer Support
OCTOBER 2019
545Before Incident
Breach
06 Oct 2019Kaiser Permanente
Kaiser Health Plan, Southern California

Data Breach at Kaiser Health Plan, Southern California

487After Incident
HIGH-58
KAI941080425
The California Office of the Attorney General reported a data breach involving Kaiser Health Plan, Southern California, on February 28, 2020. The breach occurred when a former address was incorrectly used for mailings to individuals between October 6 and December 20, 2019, potentially affecting demographic and medical information. The specific number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Demographic InformationMedical Information
DATA BREACH
Demographic InformationMedical InformationSensitivity Of Data: HighPersonally Identifiable Information: Yes
AUGUST 2019
596Before Incident
Breach
12 Aug 2019Kaiser Permanente
Kaiser Permanente

Kaiser Permanente Data Breach

538After Incident
HIGH-58
KAI228072525
The California Office of the Attorney General reported a data breach involving Kaiser Permanente on September 26, 2019. The breach occurred on August 12, 2019, when a provider’s email account containing protected health information was compromised for approximately thirteen hours. The types of information potentially exposed included names, medical record numbers, and various health-related details, but Social Security numbers and financial information were not involved.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesmedical record numbershealth-related details
DATA BREACH
namesmedical record numbershealth-related detailsSensitivity Of Data: Highnamesmedical record numbers
NOVEMBER 2017
574Before Incident
Breach
02 Nov 2017Kaiser Permanente
Kaiser Foundation Health Plan, Inc.

Kaiser Foundation Health Plan, Inc. Data Breach (2017)

516After Incident
CRITICAL-58
KAI502082925
On November 2, 2017, Kaiser Foundation Health Plan, Inc. experienced a data breach reported by the California Office of the Attorney General on December 5, 2017. The incident involved the unauthorized compromise of personal health information (PHI), though the exact number of affected individuals remains undisclosed. The breach exposed sensitive medical and personally identifiable data, posing risks such as identity theft, financial fraud, or misuse of health records. Given the nature of the compromised information—health data—this incident carries severe implications for patient privacy, trust in the healthcare provider, and potential regulatory penalties under laws like HIPAA (Health Insurance Portability and Accountability Act). The lack of clarity on the scale of the breach further complicates mitigation efforts, leaving affected individuals vulnerable to long-term consequences. Healthcare breaches of this nature often trigger investigations by regulatory bodies, legal repercussions, and reputational damage that can erode patient confidence. The exposure of PHI also heightens the risk of targeted phishing attacks or blackmail, particularly if the data includes diagnoses, treatment histories, or insurance details. Kaiser’s response—including notification protocols, remediation measures, and transparency—would be critical in determining the long-term impact on its operations and public perception.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal Health Information
DATA BREACH
Personal Health InformationNumber Of Records Exposed: UnknownSensitivity Of Data: High
AUGUST 2017
622Before Incident
Breach
09 Aug 2017Kaiser Permanente
Kaiser Foundation Health Plan

Kaiser Foundation Health Plan Data Breach (2017)

564After Incident
HIGH-58
KAI557091725
On August 9, 2017, Kaiser Foundation Health Plan experienced a data breach when an employee inadvertently emailed a document containing protected health information (PHI) to an unknown external address. The incident was reported to the California Office of the Attorney General on August 31, 2017. The breach involved the unauthorized disclosure of sensitive patient data, though the exact number of affected individuals was not specified. The exposed information likely included medical records, personal identifiers, or treatment details, posing risks such as identity theft, fraud, or reputational harm to the impacted patients. As a healthcare provider, Kaiser’s breach underscores vulnerabilities in internal data-handling protocols, particularly in securing PHI against accidental leaks. The incident did not involve ransomware or a targeted cyber attack but stemmed from human error, highlighting the need for stricter email security measures and employee training to prevent similar occurrences in the future.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Brand Reputation Impact: Potential (Healthcare Data Exposure)Identity Theft Risk: Potential (Protected Health Information)
DATA BREACH
Type Of Data Compromised: Protected Health Information (PHI)Number Of Records Exposed: UnspecifiedSensitivity Of Data: High (Health Data)
NOVEMBER 2016
656Before Incident
Breach
16 Nov 2016Kaiser Permanente
Kaiser Foundation Hospitals

Data Breach at Kaiser Foundation Hospitals

598After Incident
MEDIUM-58
KAI928072525
The California Office of the Attorney General reported a data breach involving Kaiser Foundation Hospitals on December 20, 2016. The breach, which occurred due to a system error between November 16 and 28, 2016, potentially exposed individuals' names, ages, addresses, copay information, deductible payments, and out-of-pocket expenses. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesagesaddressescopay informationdeductible paymentsout-of-pocket expenses
DATA BREACH
namesagesaddressescopay informationdeductible paymentsout-of-pocket expensesnamesagesaddresses
OCTOBER 2016
712Before Incident
Breach
12 Oct 2016Kaiser Permanente
Kaiser Permanente Health Plan, Inc.

Kaiser Permanente Health Plan Data Breach

654After Incident
LOW-58
KAI406072625
The California Office of the Attorney General reported that Kaiser Permanente Health Plan, Inc of Northern California experienced a data breach on November 7, 2016, related to an accidental exposure of protected health information on October 12-13, 2016. The breach allowed member information accessed via kp.org to be mistakenly viewable by other visitors for approximately two hours, although no Social Security numbers or banking information were compromised.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Member InformationSystems Affected: kp.org
DATA BREACH
Type Of Data Compromised: Protected Health InformationSensitivity Of Data: HighPersonally Identifiable Information: Member Information
AUGUST 2012
701Before Incident
Breach
24 Aug 2012Kaiser Permanente
Kaiser Permanente

Kaiser Permanente Data Breach

643After Incident
HIGH-58
KAI654072925
The California Office of the Attorney General reported a data breach involving Kaiser Permanente on October 29, 2012. The breach occurred on August 24, 2012, when an employee mistakenly emailed confidential employee information, including names and Social Security numbers, to an unauthorized recipient. The number of individuals affected is not specified, but the report states that no personal health information was involved.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Accidental
IMPACT
NamesSocial Security Numbers
DATA BREACH
NamesSocial Security NumbersSensitivity Of Data: High
APRIL 2012
761Before Incident
Breach
06 Apr 2012Kaiser Permanente
Kaiser Permanente

Kaiser Permanente Data Breach

697After Incident
CRITICAL-64
KAI529072625
The California Office of the Attorney General reported that Kaiser Permanente experienced a data breach on April 6, 2012, due to an employee inadvertently sending a report to a non-Kaiser Permanente email address. The reported date of the incident is April 16, 2012. The incident potentially affected patient identifiable information, although the number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Patient Identifiable Information
DATA BREACH
Type Of Data Compromised: Patient Identifiable Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kaiser Permanente ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Kaiser Permanente's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Kaiser Permanente's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kaiser Permanente ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kaiser Permanente's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?