Cerebral, Inc
ent_cb3ae75c9992e16dc04d9bd6
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
3,179,835
as filed · HHS OCR DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cerebral, Inc
- Normalized
- cerebral— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🐻California State AGas victim2023-03-06
Cerebral, Inc. disclosed that it inadvertently shared protected health information (PHI) and other personal data with third-party tracking platforms (Google, Meta, TikTok) and subcontractors via pixels and similar technologies on its websites and apps. The practice occurred from October 12, 2019, until Cerebral determined the issue on January 3, 2023. Affected data included names, contact info, IP addresses, assessment responses, treatment details, and insurance information. Cerebral disabled the tracking technologies, ceased non-compliant data sharing, and offered 12 months of credit monitoring to affected individuals.
- 🌲Washington State AGas victim2023-03-03
Cerebral, Inc, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-03 and filed notice on 2023-03-03. 86,669 Washington residents were affected. 59 days elapsed between awareness and notification. 1179 days to identify the breach. 57 days to contain the breach.
- DELAWAREHHS OCRas victim2023-03-01
Cerebral, Inc reported to HHS on 2023-03-01 a Unauthorized Access/Disclosure affecting 3,179,835 individuals. Breached information located on Network Server. The Business Associate impermissibly disclosed PHI (names, addresses, birthdates, diagnoses, treatment info) via Internet tracking technologies. Response included credit monitoring, policy revision, workforce retraining, and enhanced safeguards.