DisclosureLens
HackingHealthcareFinancial ServicesHealthcareVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIdentity (basic)Government IDHealth (basic)MediumContained

CareSource

bd_a5a734fce487738a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 27, 2023

Filed

Aug 28, 2023

To disclose

9 weeks

Affected

Not disclosed

Linked

9 filings

Confidence

65%
Full breach record for CareSource6 incidents on file

CareSource experienced a security breach involving its vendor MOVEit. On May 31, 2023, the MOVEit software was hacked, allowing an unauthorized actor to access and copy data used to manage member benefits. CareSource learned of its inclusion in the breach on June 27, 2023. The compromised data included protected health information (PHI) such as names, addresses, dates of birth, Social Security numbers, member IDs, plan names, health conditions, medications, allergies, and diagnoses. CareSource patched the software on June 1, 2023, cutting off the attacker's access. The company is conducting a full investigation and has offered two years of credit monitoring through Kroll to affected individuals.

Leak gap clock Leak >30d9 weeks discovery → filing

Incident timeline

undetected · 27 days
discovery → filing · 9 weeks / 62 days

May 31, 2023

Begins

Jun 27, 2023

Discovered

Aug 28, 2023

Filed

vs. sector median

2 wks faster

This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 60 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 239d gap

Filing propagation · 8 filings · 7 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Aug 30 (WA) — a 241-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.