CareFirst Administrators
ent_cca32173a5a15c8a8ced9ee8
Disclosures
2
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
14,538
nationwide · HHS OCR MD
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CareFirst Administrators
- Normalized
- carefirst administrators— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- MARYLANDHHS OCRas victim2022-11-18
CareFirst Administrators reported to HHS on 2022-11-18 a Hacking/IT Incident affecting 14,538 individuals. Breached information located on Email. Employees of a business associate were victims of an email phishing attack exposing PHI (names, DOB, addresses, SSNs, diagnoses, medications, claims). CE provided credit monitoring; BA implemented safeguards.
- Montana State AGas reporting2022-11-17
Conifer Value-Based Care, LLC, a business associate of CareFirst Administrators, experienced a phishing incident affecting Microsoft Office 365 email accounts between March 17-22, 2022. Unauthorized access led to exposure of PII and PHI including names, addresses, DOB, and medical info. Conifer reset passwords, blocked malicious IPs, engaged forensic investigators, and implemented MFA. Notices sent October 25, 2022.