HackingCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CareTree
bd_44a69674e55b338c · schema v1 · pii pii-v1
Full breach record for CareTree →CareTree, Inc. disclosed a cybersecurity incident affecting its patient care platform. Unauthorized access occurred on July 21, 2023, and was discovered by CareTree on August 16, 2023. The breach potentially exposed personal information, including names and government identifiers (SSN), of caretaker professionals and patients. CareTree notified law enforcement, implemented additional security measures, and offered credit monitoring services to affected individuals. Notifications were sent in late 2023.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_d3e5a7ef13ce1b8bVermont State AGfiled 2023-12-27Verified
- bd_97d6f0b94f215758New Hampshire State AGfiled 2024-01-12(16d gap)Verified
- bd_ab9056e59a633901Maine State AGfiled 2023-12-11(16d gap)Verified
- bd_1f0e8136404e11ceNew Hampshire State AGfiled 2023-12-08(19d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 42d gap
- bd_339db28c04eef715HHS OCRfiled 2023-11-15(42d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/caretree-20231227.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 27, 2023
- Raw hash
- 7bd921f78160f41ff58c2dca7dda946bf4b78f7cae4897dd8a6c83dfe398eafd
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTreenorm: caretree
Incident
- Discovered
- Aug 16, 2023
- Materiality determined
- —
- Notification sent
- Dec 27, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reporting to regulatory authorities, as required
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.