Cornerstone Care, Inc.
ent_3507f49fd8716ac2e3c3e88c
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
12,081
nationwide · HHS OCR PA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cornerstone Care, Inc.
- Normalized
- cornerstone care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2021-03-02
Cornerstone Care, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-03-02. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2021-02-25
Healthcare provider Cornerstone Care, Inc. experienced an unauthorized access incident that affected 11,487 individuals. The breach occurred on November 13, 2019, but was not discovered until January 13, 2021. The compromised information includes names and Social Security numbers. Affected individuals were notified on February 25, 2021, and offered 12 months of credit monitoring and identity protection services.
- PENNSYLVANIAHHS OCRas victim2021-02-25
Cornerstone Care, Inc. (PA) reported to HHS OCR on 2021-02-25 a Hacking/IT Incident affecting 12,081 individuals. An employee was the victim of an email phishing scheme, exposing ePHI including names, addresses, dates of birth, diagnoses, health insurance information, Social Security numbers, and other treatment information. Breached information was located in Email systems. The covered entity implemented additional safeguards and retrained staff on identifying fraudulent email communications.
- Illinois State AGas victim2021-01-01
CORNERSTONE CARE, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-094). The register records the breach as discovered on June 1, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.