DisclosureLens
Social EngineeringHealthcareTechnologyHealthcarePhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIdentity (basic)PHIHealth (basic)LowContained

Conifer Value-Based Care, LLC

bd_1d90c95ac31b399e · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 21, 2022

Filed

Nov 17, 2022

To disclose

34 weeks

Affected

50state residents only

Confidence

65%
Full breach record for Conifer Value-Based Care, LLC4 incidents on file

Conifer Value-Based Care, LLC, a business associate of CareFirst Administrators, experienced a phishing incident affecting Microsoft Office 365 email accounts between March 17-22, 2022. Unauthorized access led to exposure of PII and PHI including names, addresses, DOB, and medical info. Conifer reset passwords, blocked malicious IPs, engaged forensic investigators, and implemented MFA. Notices sent October 25, 2022.

Incident timeline

undetected · 4 days
discovery → filing · 34 weeks / 241 days

Mar 17, 2022

Begins

Mar 21, 2022

Discovered

Nov 17, 2022

Filed

vs. sector median

+22 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed50 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.