Cerebral, Inc
bd_c62c74b5661fad19 · schema v1 · pii pii-v1
Full breach record for Cerebral, Inc →Cerebral, Inc. disclosed that it inadvertently shared protected health information (PHI) and other personal data with third-party tracking platforms (Google, Meta, TikTok) and subcontractors via pixels and similar technologies on its websites and apps. The practice occurred from October 12, 2019, until Cerebral determined the issue on January 3, 2023. Affected data included names, contact info, IP addresses, assessment responses, treatment details, and insurance information. Cerebral disabled the tracking technologies, ceased non-compliant data sharing, and offered 12 months of credit monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 12, 2019
Begins
Jan 3, 2023
Discovered
Mar 6, 2023
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Washington State AGbd_c20a7d3624294b892023-03-03 · +3dVerified
- HHS OCRbd_5205f315d426cb9d2023-03-01 · +5dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Mar 1 (DE), last Mar 6 (CA) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.