Partnership HealthPlan of California, the Medi-Cal managed care plan serving Sierra, Plumas, and Nevada counties along with other Northern California counties, recently notified members that a privacy incident exposed some of their personal information. According to Partnership, new member welcome packets mailed between May and July 2026 contained information belonging to other members rather than the intended recipient.
Health plans that manage members’ personal and health information carry a responsibility to safeguard that data throughout every stage of the enrollment and communication process, including the physical mailing of welcome materials.
Partnership HealthPlan of California’s Data Breach Investigation
Partnership HealthPlan of California (PHC) is a nonprofit Medi-Cal managed care health plan that serves members across a number of Northern California counties, including Shasta County. According to a notification letter PHC sent to affected individuals, the incident involved Primary Care Physician (PCP) Selection Forms and welcome packets that were mailed to new members between May 13, 2026, and July 8, 2026. PHC’s investigation found that some of these mailings contained information belonging to members other than the person who received the envelope, meaning a recipient could see another member’s personal information rather than, or in addition to, their own.
PHC has publicly stated that the incident was discovered on July 7, 2026, and that its review ultimately determined 1,526 members had information disclosed to the wrong recipient. Of that total, 102 of the affected members are Shasta County residents, where PHC serves roughly 66,000 enrollees. PHC notified all 1,526 affected members and reported the incident to applicable regulatory agencies, including the California Attorney General, as required by law.
This kind of incident, sometimes called a mailing or fulfillment error, differs from a network intrusion or hacking incident in that no outside attacker needs to breach any computer system for personal information to be exposed. Instead, an error somewhere in the printing, sorting, or mailing process, whether at the health plan itself or at a mailing vendor it uses, results in the wrong information being placed in an envelope addressed to the wrong person. These errors are a common category of healthcare privacy incident precisely because member communications like welcome packets and enrollment forms are produced and mailed in bulk, and a batching or address-matching mistake can affect many recipients at once even though no single person’s account was ever hacked.
Health plans are required to safeguard members’ protected health information under the Health Insurance Portability and Accountability Act, commonly known as HIPAA, and a mailing error that discloses protected health information to the wrong recipient can still constitute a reportable breach under HIPAA and state law even when no hacking or malicious intrusion is involved. PHC has stated that it reviewed and strengthened its privacy and security safeguards, increased oversight of the vendors involved in producing and mailing its member communications, and provided additional workforce training as a result of this incident.
PHC disclosed that the information involved in this incident was limited to each affected member’s name, date of birth, and member identification number. The company has specifically stated that Social Security numbers, driver’s license or state identification numbers, addresses, and information about members’ treatment, diagnoses, or financial accounts were not involved. While a name, date of birth, and member ID number alone are less immediately useful to an identity thief than a Social Security number, this combination of information can still be misused, particularly in combination with other data a bad actor may obtain elsewhere, to attempt fraudulent activity or unauthorized access to a member’s account.
This is not PHC’s first reported privacy incident. The health plan reported a separate, unrelated network intrusion in 2022 that affected more than 850,000 current and former members, a substantially larger and more serious incident involving a direct breach of PHC’s computer systems rather than a mailing error. The two incidents are not connected, and the current welcome-packet mailing error should not be confused with the scale or nature of the 2022 network breach.
When Did This Breach Occur?
PHC has stated that the affected welcome packets and PCP Selection Forms were mailed between May 13, 2026, and July 8, 2026. PHC discovered the incident on July 7, 2026, and publicly disclosed it on September 4, 2026, after notifying all 1,526 affected members individually.
What Information Was Breached?
According to PHC, the information disclosed to the wrong recipient was limited to a member’s name, date of birth, and member identification number. PHC has stated that Social Security numbers, driver’s license or state identification numbers, home addresses, and information about a member’s treatment, diagnoses, or financial accounts were not involved in this incident.
What You Can Do
If you received a notification letter from Partnership HealthPlan of California, consider taking the following steps:
- Review any Explanation of Benefits or account statements you receive for unfamiliar activity
- Contact PHC Member Services at 1-800-863-4155, TTY 1-800-735-2929, with any questions or concerns
- Stay alert for phishing messages or unexpected requests for your personal information
- Report any suspicious activity to your local law enforcement agency
- File a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights were violated
File a Data Breach Lawsuit Against Partnership HealthPlan of California
If your personal information was disclosed as a result of this incident and you have experienced identity theft, fraud, or other harm, you may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.