CareTracker, Inc.
ent_338e597fc6a0567fdc788dee
Disclosures
5
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
98,774
as filed · HHS OCR OK
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareTracker, Inc.
- Normalized
- caretracker— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2025-11-12
CareTracker, Inc. d/b/a Amazing Charts notified the California AG of a security incident involving a third-party service provider. Unauthorized access to the provider's network occurred between June 15 and June 19, 2025. Affected data may include names, medical treatment/diagnosis info, physician names, medical record numbers, and health insurance information. The company retained legal counsel and cybersecurity specialists, secured the environment, and offered 12 months of credit monitoring.
- NEW YORKHHS OCRas victim2025-08-18
CareTracker, Inc. (NY, Business Associate) reported to HHS OCR on 2025-08-18 a Hacking/IT Incident affecting 501 individuals. Breached information was located on a Network Server. A business associate was present. No further details are available in the public disclosure.
- OKHHS OCRas victim2021-08-27
CareATC, Inc. (Oklahoma) reported to HHS OCR on 2021-08-27 a Hacking/IT Incident affecting 98,774 individuals via an email phishing attack that compromised employee email accounts. Exposed PHI included names, addresses, dates of birth, driver's license numbers, Social Security numbers, claims information, medications, diagnoses, and lab results. The CE notified HHS, affected individuals, and media, and offered credit monitoring. Additional safeguards and workforce retraining were implemented. Breached information located on Email.
- 🌲Washington State AGas victim2021-08-27
CareATC, Inc., a health sector entity reported a phishing incident to the Washington Attorney General. The organization became aware of the incident on 2021-06-29 and filed notice on 2021-08-27. 600 Washington residents were affected. 59 days elapsed between awareness and notification. 11 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2021-08-27
CareATC, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-08-27. The breach occurred from 6/18/2021 to 6/29/2021. 1 Montana residents were affected.