ELARA CARING
bd_401ea64a041d73c3 · schema v1 · pii pii-v1
Full breach record for ELARA CARING →3 incidents on fileElara Caring notified Montana AG of a Business Email Compromise (BEC) incident. On Dec 9, 2020, phishing emails compromised two employee accounts, allowing the attacker to send further phishing emails until Dec 16. Patient data exposed included PHI, SSNs, DOBs, financial info, and driver's licenses. No evidence of data misuse or malware. Elara engaged forensic specialists, reported to FBI, implemented MFA, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 9, 2020
Begins
Dec 9, 2020
Discovered
Feb 17, 2021
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_af575bdfe4a4baad2021-02-24 · +7dVerified
- Massachusetts State AGbd_27321bb2bdb2fe782021-03-01 · +12dVerified
- Illinois State AGbd_07d0d0585d4e0f902021-01-01 · +47dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Mar 1 (MA) — a 59-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.