HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
CareTree, Inc. on behalf of affected customers
bd_727e34824e5007c9 · schema v1 · pii pii-v1
Full breach record for CareTree, Inc. on behalf of affected customers →CareTree, Inc. notified the California Attorney General of an incident where an unauthorized actor gained access to patient care information on July 21, 2023. CareTree became aware of suspicious activity on August 16, 2023. Affected data may include names, addresses, driver's licenses, SSNs, financial account info, dates of birth, and medical/health insurance information. The company secured the platform, implemented additional cybersecurity measures, reported to law enforcement, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577738
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 11, 2023
- Raw hash
- f8310b89458edacaeae47bedec4bf1f0a14666f92706d1b0fa123111c2bdaefc
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTree, Inc. on behalf of affected customersnorm: caretree inc on behalf of affected customers
Incident
- Discovered
- Aug 16, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reporting to regulatory authorities, as required
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.