HackingData ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICLowContained
BAYADA Home Health Care, Inc.
bd_9db79ee86e2351a5 · schema v1 · pii pii-v1
Full breach record for BAYADA Home Health Care, Inc. →BAYADA Home Health Care, Inc. notified the California Attorney General of a cybersecurity event where an unauthorized actor accessed systems and copied data between February 18 and March 2, 2026. BAYADA became aware of the incident on March 2, 2026. The breach involved personal information including names and potentially protected health information, given the company's role in home health care. BAYADA engaged forensic investigators, reported to federal law enforcement and HHS, and is offering credit monitoring services to affected individuals.
California clockDiscovered Mar 2, 2026 → Notified Jul 17, 2026137d ✗ CA 30-day late20 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_951efdd5e95bac78South Carolina State AGfiled 2026-07-17Verified
- bd_e49e19ce5cef03e5Delaware State AGfiled 2026-07-17Verified
- bd_ed5a2dba88565668Vermont State AGfiled 2026-07-17Verified
- bd_a6462b4c4607b635Texas State AGfiled 2026-07-21(4d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_abbd4542ef2e9ed5Massachusetts State AGfiled 2026-07-01(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-626658
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2026
- Raw hash
- adaa28641a6c3cb2b4c4aa1ccc0f9a5fefefdbdfc61b438cede7c3fed8f6dfa5
Reporting entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Victim entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Incident
- Discovered
- Mar 2, 2026
- Materiality determined
- —
- Notification sent
- Jul 17, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the event to appropriate governmental agencies, including federal law enforcement and the U.S. Department of Health and Human Services
Compliance
- Time to disclose
- 20 weeks(137 days from discovery to filing)
- Compliance flags
- CA 30-day late · 137dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 2, 2026→ Notified: Jul 17, 2026137d 30 calendar days CA 30-day late California Consumers notified: Jul 17, 2026→ AG copy submitted: Jul 17, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.