CareSource
bd_023953673f35b827 · schema v1 · pii pii-v1
Full breach record for CareSource →6 incidents on fileCareSource, a managed care organization, reported a breach involving its MOVEit file transfer vendor. The CL0P ransomware group exploited a vulnerability on May 31, 2023, exfiltrating data including PHI, SSNs, and member details. CareSource discovered the breach on June 27, 2023, patched the system, and engaged Kroll for forensics. 70 New Hampshire residents were affected. Notifications began August 25, 2023, offering credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Jun 27, 2023
Discovered
Aug 30, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_92cee760ff4463cd2023-06-29 · +62dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Washington State AGbd_8cae43083631f0182023-08-30Verified by operator
- Massachusetts State AGbd_6a936f6fd472b50c2023-08-28 · +2dVerified by operator
- California State AGbd_a5a734fce487738a2023-08-28 · +2dVerified by operator
- Vermont State AGbd_6c68eb604349c96d2023-08-25 · +5dVerified by operator
Show 3 more filings ↓Show fewer ↑up to 241d gap
- HHS OCRbd_15516622e95b67bb2023-07-27 · +34dVerified by operator
- New Hampshire State AGbd_ad59de38582addd52023-07-18 · +43dVerified by operator
- Illinois State AGbd_40d83cd3b7afec812023-01-01 · +241dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Aug 30 (NH) — a 241-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.