HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHIMediumContained
CareTree
bd_b0b9e4947aa838c9 · schema v1 · pii pii-v1
Full breach record for CareTree →CareTree, Inc. reported a data breach where an unauthorized actor gained access to patient care information on July 21, 2023. The company became aware of suspicious activity on August 16, 2023. Affected data may include names, addresses, driver's licenses, Social Security numbers, financial account information, dates of birth, and medical/health insurance information. CareTree secured the platform, launched an investigation, implemented additional cybersecurity measures, and offered credit monitoring to affected individuals. This is a supplemental notice.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581016
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2024
- Raw hash
- 5f550d409c40c1227b46d5853bce477f8b92dfcfc60bca519c286628c8680fa3
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTreenorm: caretree
Incident
- Discovered
- Aug 16, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPHI
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reporting to regulatory authorities, as required
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.