CareTree
ent_c5df3653e816941808d72442
Disclosures
8
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
15,846
as filed · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareTree
- Normalized
- caretree— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🐻California State AGas victim2024-02-14
CareTree, Inc. reported a data breach where an unauthorized actor gained access to patient care information on July 21, 2023. The company became aware of suspicious activity on August 16, 2023. Affected data may include names, addresses, driver's licenses, Social Security numbers, financial account information, dates of birth, and medical/health insurance information. CareTree secured the platform, launched an investigation, implemented additional cybersecurity measures, and offered credit monitoring to affected individuals. This is a supplemental notice.
- ⛰️New Hampshire State AGas victim2024-01-12
CareTree, Inc. issued a supplemental notice to New Hampshire residents regarding a data breach. Unauthorized access occurred on July 21, 2023, detected on August 16, 2023. The incident involved unauthorized access to personal information of individuals using the CareTree platform. CareTree notified law enforcement, implemented additional cybersecurity measures, and provided credit monitoring services to affected individuals.
- ⛰️New Hampshire State AGas victim2023-12-27
CareTree, Inc. disclosed a cybersecurity incident affecting its patient care platform. Unauthorized access occurred on July 21, 2023, and was discovered by CareTree on August 16, 2023. The breach potentially exposed personal information, including names and government identifiers (SSN), of caretaker professionals and patients. CareTree notified law enforcement, implemented additional security measures, and offered credit monitoring services to affected individuals. Notifications were sent in late 2023.
- 🍁Vermont State AGas victim2023-12-27
CareTree, Inc. notified consumers of a data breach where an unauthorized actor accessed the CareTree platform. The incident occurred on July 21, 2023, and was discovered on August 16, 2023. Potentially affected data includes names, addresses, SSNs, driver's licenses, financial account info, and medical/health insurance data. CareTree engaged law enforcement, implemented additional cybersecurity measures, and offered Equifax credit monitoring services.
- 🐻California State AGas reporting2023-12-11
CareTree, Inc. notified the California Attorney General of an incident where an unauthorized actor gained access to patient care information on July 21, 2023. CareTree became aware of suspicious activity on August 16, 2023. Affected data may include names, addresses, driver's licenses, SSNs, financial account info, dates of birth, and medical/health insurance information. The company secured the platform, implemented additional cybersecurity measures, reported to law enforcement, and offered credit monitoring.
- 🦞Maine State AGas victim2023-12-11
CareTree, Inc., a third-party vendor, reported a data breach caused by a hacking incident. The breach was discovered on October 13, 2023, and is believed to have occurred on July 21, 2023. The incident resulted in the compromise of names and financial account details. CareTree notified affected individuals on December 11, 2023, and offered one year of credit monitoring and identity theft insurance services through Epiq.
- ⛰️New Hampshire State AGas victim2023-12-08
CareTree, Inc. disclosed a cybersecurity incident affecting approximately 5,856 individuals. Unauthorized access occurred between July 21, 2023, and August 16, 2023. The breach involved unauthorized access to the CareTree platform, potentially exposing patient care information, including names, Social Security numbers, and financial account data. CareTree notified federal law enforcement, implemented additional security safeguards, and provided credit monitoring services through Equifax to affected individuals. The incident was reported to the HHS OCR as a breach affecting 500 or more individuals.
- ILHHS OCRas victim2023-11-15
CareTree, Inc. (IL), a business associate, reported to HHS OCR on 2023-11-15 a ransomware incident affecting 15,846 individuals. Breached PHI on network servers included names, addresses, dates of birth, drivers' license and SSNs, diagnoses, conditions, lab results, medications, and financial/medical information. CareTree notified HHS, affected individuals, media, and posted substitute notice. Additional administrative and technical safeguards were implemented. OCR provided technical assistance.