CareATC, Inc.
ent_2b258357fa04feaac3e815b7
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
98,774
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareATC, Inc.
- Normalized
- careatc— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Indiana State AGas victim2021-08-27
CareATC, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-06-18 and was reported on 2021-08-27. 1 Indiana residents were affected. 98,774 individuals affected in total.
- OKLAHOMAHHS OCRas victim2021-08-27
CareATC, Inc. (Oklahoma) reported to HHS OCR on 2021-08-27 a Hacking/IT Incident affecting 98,774 individuals via an email phishing attack that compromised employee email accounts. Exposed PHI included names, addresses, dates of birth, driver's license numbers, Social Security numbers, claims information, medications, diagnoses, and lab results. The CE notified HHS, affected individuals, and media, and offered credit monitoring. Additional safeguards and workforce retraining were implemented. Breached information located on Email.
- Washington State AGas victim2021-08-27
CareATC, Inc. notified Washington residents of a data breach involving unauthorized access to two employee email accounts. The incident occurred between June 18 and June 29, 2021, and was discovered on June 29, 2021. Approximately 600 Washington residents were affected, with their names, dates of birth, health insurance information, and medical diagnosis/treatment data potentially exposed. CareATC engaged forensic specialists, provided one year of credit monitoring through Kroll, and implemented additional employee training.
- Montana State AGas victim2021-08-27
CareATC, Inc. notified Montana residents of a data breach involving unauthorized access to two employee email accounts between June 18 and June 29, 2021. The incident was discovered on June 29, 2021, following suspicious activity. The breach potentially exposed personal information of individuals whose data was present in the affected emails. No evidence of misuse was found.