MalwareRansomwareData EncryptedData ExfiltratedIDENTITY_BASICHEALTH_BASICLowContained
CareSource
bd_edd2b075436c532c · schema v1 · pii pii-v1
Full breach record for CareSource →CareSource reported a cybersecurity incident involving its third-party vendor, OneTouchPoint (OTP). On April 28, 2022, OTP systems were locked by an attacker, indicating a ransomware attack. Files containing member personal information (names, addresses, member IDs, age, gender) and health data (diagnoses, medications, allergies, health screenings, vital signs, immunizations, plan names) were encrypted. OTP shut down and rebuilt systems, adding technical controls. No SSN or financial account data was impacted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555811
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2022
- Raw hash
- b4ae1fe96973540f6edd6bd287584bd98410442f8c6daf78df1b04f7b7f65364
Reporting entity
- Name
- OneTouchPoint, Inc.norm: onetouchpoint
- Domain
- onetouchpoint.com
Victim entity
- Name
- CareSourcenorm: caresource
- Domain
- caresource.com
Incident
- Discovered
- Apr 28, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.