DisclosureLens
Social EngineeringHealthcareHealthcarePhishingData ExfiltratedCustomer Data InvolvedIdentity (basic)Health (basic)PHILowContained

CareATC, Inc.

bd_a3b3b4582032788c · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 29, 2021

Filed

Aug 27, 2021

To disclose

8 weeks

Affected

600state residents only

Linked

4 filings

Confidence

68%
Full breach record for CareATC, Inc.

CareATC, Inc. notified Washington residents of a data breach involving unauthorized access to two employee email accounts. The incident occurred between June 18 and June 29, 2021, and was discovered on June 29, 2021. Approximately 600 Washington residents were affected, with their names, dates of birth, health insurance information, and medical diagnosis/treatment data potentially exposed. CareATC engaged forensic specialists, provided one year of credit monitoring through Kroll, and implemented additional employee training.

Washington clock WA AG >30d8 weeks discovery → filing

Incident timeline

undetected · 11 days
discovery → filing · 8 weeks / 59 days

Jun 18, 2021

Begins

Jun 29, 2021

Discovered

Aug 27, 2021

Filed

vs. sector median

4 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Indiana State AGAug 27 · first
HHS OCRAug 27 · first
Montana State AGAug 27 · first
Washington State AGAug 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.