Were you recently affected by a data breach?

Partnership HealthPlan of California Data Breach

Partnership HealthPlan of California disclosed that welcome packets mailed to new members between May and July 2026 contained other members’ personal information, affecting 1,526 individuals. Exposed data included names, dates of birth, and member ID numbers, but not Social Security numbers.

Partnership HealthPlan of California
Date of Breach: May 13, 2026 to July 8, 2026 (mailings); discovered July 7, 2026
CAU logo

Who was affected:

Clients of Partnership HealthPlan of California

Impacted Data:

Names, dates of birth, member identification numbers

Partnership HealthPlan of California, the Medi-Cal managed care plan serving Sierra, Plumas, and Nevada counties along with other Northern California counties, recently notified members that a privacy incident exposed some of their personal information. According to Partnership, new member welcome packets mailed between May and July 2026 contained information belonging to other members rather than the intended recipient.

Health plans that manage members’ personal and health information carry a responsibility to safeguard that data throughout every stage of the enrollment and communication process, including the physical mailing of welcome materials.

Partnership HealthPlan of California’s Data Breach Investigation

Partnership HealthPlan of California (PHC) is a nonprofit Medi-Cal managed care health plan that serves members across a number of Northern California counties, including Shasta County. According to a notification letter PHC sent to affected individuals, the incident involved Primary Care Physician (PCP) Selection Forms and welcome packets that were mailed to new members between May 13, 2026, and July 8, 2026. PHC’s investigation found that some of these mailings contained information belonging to members other than the person who received the envelope, meaning a recipient could see another member’s personal information rather than, or in addition to, their own.

PHC has publicly stated that the incident was discovered on July 7, 2026, and that its review ultimately determined 1,526 members had information disclosed to the wrong recipient. Of that total, 102 of the affected members are Shasta County residents, where PHC serves roughly 66,000 enrollees. PHC notified all 1,526 affected members and reported the incident to applicable regulatory agencies, including the California Attorney General, as required by law.

This kind of incident, sometimes called a mailing or fulfillment error, differs from a network intrusion or hacking incident in that no outside attacker needs to breach any computer system for personal information to be exposed. Instead, an error somewhere in the printing, sorting, or mailing process, whether at the health plan itself or at a mailing vendor it uses, results in the wrong information being placed in an envelope addressed to the wrong person. These errors are a common category of healthcare privacy incident precisely because member communications like welcome packets and enrollment forms are produced and mailed in bulk, and a batching or address-matching mistake can affect many recipients at once even though no single person’s account was ever hacked.

Health plans are required to safeguard members’ protected health information under the Health Insurance Portability and Accountability Act, commonly known as HIPAA, and a mailing error that discloses protected health information to the wrong recipient can still constitute a reportable breach under HIPAA and state law even when no hacking or malicious intrusion is involved. PHC has stated that it reviewed and strengthened its privacy and security safeguards, increased oversight of the vendors involved in producing and mailing its member communications, and provided additional workforce training as a result of this incident.

PHC disclosed that the information involved in this incident was limited to each affected member’s name, date of birth, and member identification number. The company has specifically stated that Social Security numbers, driver’s license or state identification numbers, addresses, and information about members’ treatment, diagnoses, or financial accounts were not involved. While a name, date of birth, and member ID number alone are less immediately useful to an identity thief than a Social Security number, this combination of information can still be misused, particularly in combination with other data a bad actor may obtain elsewhere, to attempt fraudulent activity or unauthorized access to a member’s account.

This is not PHC’s first reported privacy incident. The health plan reported a separate, unrelated network intrusion in 2022 that affected more than 850,000 current and former members, a substantially larger and more serious incident involving a direct breach of PHC’s computer systems rather than a mailing error. The two incidents are not connected, and the current welcome-packet mailing error should not be confused with the scale or nature of the 2022 network breach.

When Did This Breach Occur?

PHC has stated that the affected welcome packets and PCP Selection Forms were mailed between May 13, 2026, and July 8, 2026. PHC discovered the incident on July 7, 2026, and publicly disclosed it on September 4, 2026, after notifying all 1,526 affected members individually.

What Information Was Breached?

According to PHC, the information disclosed to the wrong recipient was limited to a member’s name, date of birth, and member identification number. PHC has stated that Social Security numbers, driver’s license or state identification numbers, home addresses, and information about a member’s treatment, diagnoses, or financial accounts were not involved in this incident.

What You Can Do

If you received a notification letter from Partnership HealthPlan of California, consider taking the following steps:

  • Review any Explanation of Benefits or account statements you receive for unfamiliar activity
  • Contact PHC Member Services at 1-800-863-4155, TTY 1-800-735-2929, with any questions or concerns
  • Stay alert for phishing messages or unexpected requests for your personal information
  • Report any suspicious activity to your local law enforcement agency
  • File a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights were violated

File a Data Breach Lawsuit Against Partnership HealthPlan of California

If your personal information was disclosed as a result of this incident and you have experienced identity theft, fraud, or other harm, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's Office on September 18, 2026
Date of Breach: May 13, 2026 to July 8, 2026 (mailings); discovered July 7, 2026
Date of Breach: On or about June 22, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.