HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
BAYADA Home Health Care, Inc.
bd_abbd4542ef2e9ed5 · schema v1 · pii pii-v1
Full breach record for BAYADA Home Health Care, Inc. →BAYADA Home Health Care, Inc. disclosed a cybersecurity event affecting individuals' confidential information. Unauthorized actors accessed systems and copied data between Feb 18 and Mar 2, 2026. BAYADA engaged forensic and data review specialists, notifying federal law enforcement and HHS. Affected data includes names and government identifiers. Credit monitoring services are offered.
Massachusetts clock✗ MA AG >90d17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_951efdd5e95bac78South Carolina State AGfiled 2026-07-17(16d gap)Verified
- bd_9db79ee86e2351a5California State AGfiled 2026-07-17(16d gap)Candidate
- bd_e49e19ce5cef03e5Delaware State AGfiled 2026-07-17(16d gap)Verified
- bd_ed5a2dba88565668Vermont State AGfiled 2026-07-17(16d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 20d gap
- bd_a6462b4c4607b635Texas State AGfiled 2026-07-21(20d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1173-bayada-home-health-care-inc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- 2072771f4d234886c690309ee8d92caef6ca4375b0dff341aebdf043ea269b47
Reporting entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Victim entity
- Name
- BAYADA Home Health Care, Inc.norm: bayada home health care
Incident
- Discovered
- Mar 2, 2026
- Materiality determined
- —
- Notification sent
- Jul 17, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the event to appropriate governmental agencies, including federal law enforcement and the U.S. Department of Health and Human Services
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.