CareSource
bd_a5a734fce487738a · schema v1 · pii pii-v1
Full breach record for CareSource →CareSource experienced a security breach involving its vendor MOVEit. On May 31, 2023, the MOVEit software was hacked, allowing an unauthorized actor to access and copy data used to manage member benefits. CareSource learned of its inclusion in the breach on June 27, 2023. The compromised data included protected health information (PHI) such as names, addresses, dates of birth, Social Security numbers, member IDs, plan names, health conditions, medications, allergies, and diagnoses. CareSource patched the software on June 1, 2023, cutting off the attacker's access. The company is conducting a full investigation and has offered two years of credit monitoring through Kroll to affected individuals.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8cae43083631f018Washington State AGfiled 2023-08-30(2d gap)Candidate
- bd_6c68eb604349c96dVermont State AGfiled 2023-08-25(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572498
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- 91d477aaf4244bcd0ba449ede9956ea4199b1c103510a6dd13bead382cf3f1b2
Reporting entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Victim entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Incident
- Discovered
- Jun 27, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.