DisclosureLens
HackingHealthcareHealthcareVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIdentity (basic)Government IDMediumContained

Caring Communities

bd_65ad819fa9d60385 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2023

Filed

Sep 27, 2023

To disclose

16 weeks

Affected

1state residents only

Linked

3 filings

Confidence

64%
Full breach record for Caring Communities2 incidents on file

Caring Communities notified individuals of a third-party vendor breach involving MOVEit software compromise on June 6, 2023. The incident exposed names, addresses, and Social Security numbers. Caring Communities' own network was not impacted. Remediation included patching the vulnerability and adding security layers. Credit monitoring services were offered.

Incident timeline

discovery → filing · 16 weeks / 113 days

Jun 6, 2023

Begins

Jun 6, 2023

Discovered

Sep 27, 2023

Filed

vs. sector median

+4 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGSep 27 · first
Massachusetts State AGSep 27 · first
Montana State AGSep 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.