HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
BAYADA Home Health Care, Inc.
bd_951efdd5e95bac78 · schema v1 · pii pii-v1
Full breach record for BAYADA Home Health Care, Inc. →BAYADA Home Health Care, Inc. disclosed a cybersecurity event affecting patient data. Unauthorized access occurred between Feb 18 and March 2, 2026, with discovery on March 2, 2026. The incident involved the copying of patient names and other personal information. BAYADA engaged forensic investigators and notified federal law enforcement and HHS. Affected individuals are offered credit monitoring services. The notice covers residents in multiple states, including South Carolina, New York, and North Carolina.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_9db79ee86e2351a5California State AGfiled 2026-07-17Candidate
- bd_e49e19ce5cef03e5Delaware State AGfiled 2026-07-17Verified
- bd_ed5a2dba88565668Vermont State AGfiled 2026-07-17Verified
- bd_a6462b4c4607b635Texas State AGfiled 2026-07-21(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_abbd4542ef2e9ed5Massachusetts State AGfiled 2026-07-01(16d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20Bayada%20Home%20Health%20Care%2C%20Inc..pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2026
- Raw hash
- 255e3baccba52a0560ba2182f5ef05111826d690419b59eaf54d317dab20adad
Reporting entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Victim entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Incident
- Discovered
- Mar 2, 2026
- Materiality determined
- —
- Notification sent
- Jul 17, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- reported the event to appropriate governmental agencies, including federal law enforcement and the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 20 weeks(137 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.