HackingTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPIIMediumContained
CareTree
bd_d3e5a7ef13ce1b8b · schema v1 · pii pii-v1
Full breach record for CareTree →CareTree, Inc. notified consumers of a data breach where an unauthorized actor accessed the CareTree platform. The incident occurred on July 21, 2023, and was discovered on August 16, 2023. Potentially affected data includes names, addresses, SSNs, driver's licenses, financial account info, and medical/health insurance data. CareTree engaged law enforcement, implemented additional cybersecurity measures, and offered Equifax credit monitoring services.
Vermont clock✗ VT AG >45 bday19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_44a69674e55b338cNew Hampshire State AGfiled 2023-12-27Verified
- bd_97d6f0b94f215758New Hampshire State AGfiled 2024-01-12(16d gap)Verified
- bd_ab9056e59a633901Maine State AGfiled 2023-12-11(16d gap)Verified
- bd_1f0e8136404e11ceNew Hampshire State AGfiled 2023-12-08(19d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 42d gap
- bd_339db28c04eef715HHS OCRfiled 2023-11-15(42d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-27-caretree-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 27, 2023
- Raw hash
- 7569d215002da5bba1a551a780754ac2cfc56ab5b55842066bf9c73a4409721f
Reporting entity
- Name
- CareTreenorm: caretree
Victim entity
- Name
- CareTreenorm: caretree
Incident
- Discovered
- Aug 16, 2023
- Materiality determined
- —
- Notification sent
- Dec 27, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported this incident to law enforcementreporting to regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(133 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.