Cerebral, Inc
ent_cb3ae75c9992e16dc04d9bd6
Disclosures
3
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,179,835
nationwide · HHS OCR DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cerebral, Inc
- Normalized
- cerebral— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- California State AGas victim2023-03-06
Cerebral, Inc. disclosed that it inadvertently shared protected health information (PHI) and other personal data with third-party tracking platforms (Google, Meta, TikTok) and subcontractors via pixels and similar technologies on its websites and apps. The practice occurred from October 12, 2019, until Cerebral determined the issue on January 3, 2023. Affected data included names, contact info, IP addresses, assessment responses, treatment details, and insurance information. Cerebral disabled the tracking technologies, ceased non-compliant data sharing, and offered 12 months of credit monitoring to affected individuals.
- Washington State AGas victim2023-03-03
Cerebral, Inc. disclosed unauthorized sharing of PHI and PII via third-party tracking pixels and subcontractors from Oct 2023 to Jan 2023. 86,669 Washington residents affected. Data included names, DOB, health info, and insurance details. Incident discovered Jan 3, 2023. Notifications sent March 1, 2023.
- DELAWAREHHS OCRas victim2023-03-01
Cerebral, Inc reported to HHS on 2023-03-01 a Unauthorized Access/Disclosure affecting 3,179,835 individuals. Breached information located on Network Server. The Business Associate impermissibly disclosed PHI (names, addresses, birthdates, diagnoses, treatment info) via Internet tracking technologies. Response included credit monitoring, policy revision, workforce retraining, and enhanced safeguards.