Conifer Value-Based Care, LLC
ent_6bb22a1802a38bb9bf433193
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
20,642
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Conifer Value-Based Care, LLC
- Normalized
- conifer value based care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- California State AGas victim2025-12-18
Conifer Value-Based Care, LLC reported that an unauthorized third party gained access to an employee's Microsoft Office 365 business email account on August 28-29, 2025. The incident involved personal information of patients and guarantors, potentially including names, addresses, and health-related data, but excluded SSNs, financial accounts, and passwords. Conifer contained the threat, launched an investigation, and notified affected healthcare providers and plans. No misuse of information was reported.
- TEXASHHS OCRas victim2025-12-18
Conifer Value-Based Care, LLC (a Business Associate, TX) reported to HHS on 2025-12-18 a Hacking/IT Incident affecting 12,206 individuals. Several employees were targets of an email phishing scheme that compromised PHI including clinical, demographic, and financial information. Breached information located on Email. The BA notified HHS, affected individuals, and media, provided substitute notice, offered credit monitoring, implemented additional safeguards, and retrained workforce members.
- Illinois State AGas victim2025-12-01
CONIFER VALUE-BASED CARE, LLC filed a data-breach notice with the Illinois Attorney General in December 2025 (case 25-12-669). The register records the breach as discovered on December 15, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2022-11-17
Conifer Value-Based Care, LLC, a business associate of CareFirst Administrators, experienced a phishing incident affecting Microsoft Office 365 email accounts between March 17-22, 2022. Unauthorized access led to exposure of PII and PHI including names, addresses, DOB, and medical info. Conifer reset passwords, blocked malicious IPs, engaged forensic investigators, and implemented MFA. Notices sent October 25, 2022.
- CALIFORNIAHHS OCRas victim2022-07-26
Conifer Value-Based Care, LLC (CA) reported to HHS on 2022-07-26 a Hacking/IT Incident (email phishing scheme) affecting 20,642 individuals. Several employees were targeted via phishing, exposing PHI including names, addresses, dates of birth, diagnoses, and other treatment information. Breached information located in Email. The CE notified HHS and affected individuals, offered credit monitoring, retrained staff on email security, and implemented additional safeguards.