Conifer Value-Based Care, LLC
ent_6bb22a1802a38bb9bf433193
Disclosures
3
State AG · HHS OCR · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
20,642
as filed · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Conifer Value-Based Care, LLC
- Normalized
- conifer value based care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🐻California State AGas victim2025-12-18
Conifer Value-Based Care, LLC reported that an unauthorized third party gained access to an employee's Microsoft Office 365 business email account on August 28-29, 2025. The incident involved personal information of patients and guarantors, potentially including names, addresses, and health-related data, but excluded SSNs, financial accounts, and passwords. Conifer contained the threat, launched an investigation, and notified affected healthcare providers and plans. No misuse of information was reported.
- TEXASHHS OCRas victim2025-12-18
Conifer Value-Based Care, LLC (a Business Associate, TX) reported to HHS on 2025-12-18 a Hacking/IT Incident affecting 12,206 individuals. Several employees were targets of an email phishing scheme that compromised PHI including clinical, demographic, and financial information. Breached information located on Email. The BA notified HHS, affected individuals, and media, provided substitute notice, offered credit monitoring, implemented additional safeguards, and retrained workforce members.
- CALIFORNIAHHS OCRas victim2022-07-26
Conifer Value-Based Care, LLC (CA) reported to HHS on 2022-07-26 a Hacking/IT Incident (email phishing scheme) affecting 20,642 individuals. Several employees were targeted via phishing, exposing PHI including names, addresses, dates of birth, diagnoses, and other treatment information. Breached information located in Email. The CE notified HHS and affected individuals, offered credit monitoring, retrained staff on email security, and implemented additional safeguards.