CareTree
bd_1f0e8136404e11ce · schema v1 · pii pii-v1
Full breach record for CareTree →CareTree, Inc. disclosed a cybersecurity incident affecting approximately 5,856 individuals. Unauthorized access occurred between July 21, 2023, and August 16, 2023. The breach involved unauthorized access to the CareTree platform, potentially exposing patient care information, including names, Social Security numbers, and financial account data. CareTree notified federal law enforcement, implemented additional security safeguards, and provided credit monitoring services through Equifax to affected individuals. The incident was reported to the HHS OCR as a breach affecting 500 or more individuals.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_ab9056e59a633901Maine State AGfiled 2023-12-11(3d gap)Verified
- bd_44a69674e55b338cNew Hampshire State AGfiled 2023-12-27(19d gap)Verified
- bd_d3e5a7ef13ce1b8bVermont State AGfiled 2023-12-27(19d gap)Verified
- bd_339db28c04eef715HHS OCRfiled 2023-11-15(23d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 35d gap
- bd_97d6f0b94f215758New Hampshire State AGfiled 2024-01-12(35d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/caretree-20231208.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2023
- Raw hash
- de7e45b6808db1fe6871c03d675b770b75b95b7dffd823c07ff9dfb05304d580
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTreenorm: caretree
Incident
- Discovered
- Aug 16, 2023
- Materiality determined
- —
- Notification sent
- Nov 15, 2023
- Affected individuals
- 5,856
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the eventProviding written notice on behalf of customers of this incident to relevant state and federal regulators, as necessaryNotifying the U.S. Department of Health and Human Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(114 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.