ILMalwareHealthcareHealthcareRansomwareCapture Stored DataBusiness Associate (HIPAA)Customer Data InvolvedData EncryptedData ExfiltratedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTHighContained
CareTree
bd_339db28c04eef715 · schema v1 · pii pii-v1
Full breach record for CareTree →CareTree, Inc. (IL), a business associate, reported to HHS OCR on 2023-11-15 a ransomware incident affecting 15,846 individuals. Breached PHI on network servers included names, addresses, dates of birth, drivers' license and SSNs, diagnoses, conditions, lab results, medications, and financial/medical information. CareTree notified HHS, affected individuals, media, and posted substitute notice. Additional administrative and technical safeguards were implemented. OCR provided technical assistance.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1f0e8136404e11ceNew Hampshire State AGfiled 2023-12-08(23d gap)Verified
- bd_ab9056e59a633901Maine State AGfiled 2023-12-11(26d gap)Verified
- bd_44a69674e55b338cNew Hampshire State AGfiled 2023-12-27(42d gap)Verified
- bd_d3e5a7ef13ce1b8bVermont State AGfiled 2023-12-27(42d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 58d gap
- bd_97d6f0b94f215758New Hampshire State AGfiled 2024-01-12(58d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 15, 2023
- Raw hash
- 3a5a75a3bb2cd76f069cd2b92a236e81f167fa1b3838763a27fbb1f9294ea9c1
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTreenorm: caretree
- Industry
- Healthcaresource default
Incident
- Discovered
- Oct 13, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 15,846
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR — technical assistance provided
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Oct 13, 2023→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.