HackingData MishandlingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Elara Caring
bd_7bf06e69b1fa254f · schema v1 · pii pii-v1
Full breach record for Elara Caring →Elara Caring notified Massachusetts residents of a data security incident involving a third-party vendor. Between November 4-6 and November 14-17, 2025, an unauthorized actor accessed patient documents containing personal information, including Social Security numbers. Elara terminated the vendor relationship, conducted a security review, and provided 24 months of complimentary credit monitoring via Cyberscout/TransUnion. The incident was discovered in March 2026, with notifications sent in May 2026.
Massachusetts clock⏱ MA AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_cf4d884363280d30HHS OCRfiled 2026-05-12(11d gap)Verified
- bd_8f9a1c733571d4e4Texas State AGfiled 2026-05-14(13d gap)Verified
- bd_38fb898212189fbeHHS OCRfiled 2026-06-23(53d gap)Verified
- bd_be7d391fb5a6fbfaTexas State AGfiled 2026-06-25(55d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-769-elara-caring/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- a7f096c79e005e6e45b926abec5c2535286865b89a476d3c4230d5696978d53f
Reporting entity
- Name
- Elara Caringnorm: elara caring
Victim entity
- Name
- Elara Caringnorm: elara caring
Incident
- Discovered
- Mar 12, 2026
- Materiality determined
- —
- Notification sent
- May 12, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.