CareSource
ent_efed378fa56de50e108c49a7
Disclosures
18
State AG · HHS OCR · Leak Site · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
3,180,537
nationwide · HHS OCR OH
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- CareSource
- Normalized
- caresource— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- caresource.com
Disclosure history (18)newest first
- New Hampshire State AGas victim2023-08-30
CareSource, a managed care organization, reported a breach involving its MOVEit file transfer vendor. The CL0P ransomware group exploited a vulnerability on May 31, 2023, exfiltrating data including PHI, SSNs, and member details. CareSource discovered the breach on June 27, 2023, patched the system, and engaged Kroll for forensics. 70 New Hampshire residents were affected. Notifications began August 25, 2023, offering credit monitoring.
- Washington State AGas victim2023-08-30
CareSource disclosed a breach affecting 581 Washington residents. Unauthorized access occurred on May 31, 2023, via a vulnerability in MOVEit software used by a vendor. CareSource was identified as a victim on June 27, 2023. Stolen data included PHI, SSNs, and PII. CareSource patched the software and offered two years of credit monitoring via Kroll.
- Massachusetts State AGas victim2023-08-28
CareSource reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-28. 389 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-08-28
CareSource experienced a security breach involving its vendor MOVEit. On May 31, 2023, the MOVEit software was hacked, allowing an unauthorized actor to access and copy data used to manage member benefits. CareSource learned of its inclusion in the breach on June 27, 2023. The compromised data included protected health information (PHI) such as names, addresses, dates of birth, Social Security numbers, member IDs, plan names, health conditions, medications, allergies, and diagnoses. CareSource patched the software on June 1, 2023, cutting off the attacker's access. The company is conducting a full investigation and has offered two years of credit monitoring through Kroll to affected individuals.
- Vermont State AGas victim2023-08-25
CareSource disclosed a data breach affecting its members due to a vulnerability in Progress Software's MOVEit transfer software. The incident, discovered on June 27, 2023, involved the exfiltration of protected health information (PHI) and personally identifiable information (PII), including SSNs and health conditions. CareSource patched the software and engaged Kroll to provide two years of credit monitoring to affected individuals.
- OHIOHHS OCRas victim2023-07-27
CareSource reported to HHS on 2023-07-27 a Hacking/IT Incident affecting 3,180,537 individuals. Breached information located on Network Server. A software application used by its vendor exposed PHI including names, DOB, addresses, SSNs, diagnoses, and claims.
- New Hampshire State AGas victim2023-07-18
CareSource Management Services LLC reported a security incident involving its vendor, Vitality Group, LLC. On May 30, 2023, a bad actor exploited a vulnerability in MOVEit software to access a server housing CareSource data. Vitality discovered the access on June 1, 2023, disconnected the server, and initiated a forensic investigation. The incident impacted 6 New Hampshire residents, exposing SSNs, names, DOBs, and gender. Vitality patched the vulnerability, reset passwords, and offered credit monitoring.
- GLOBALLeak Siteas victim2023-06-29
CareSource - Health Care with Heart
- Illinois State AGas victim2023-01-01
CARESOURCE filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-607). The register records the breach as discovered on May 31, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGas victim2022-08-02
CareSource reported a data breach to the Indiana Attorney General. The breach occurred on 2022-04-27 and was reported on 2022-08-02. 146,949 Indiana residents were affected. 1,436,599 individuals affected in total.
- Massachusetts State AGas victim2022-08-02
CareSource reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-08-02. 147 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2022-08-01
CareSource notified California residents of a cybersecurity incident at its vendor, OneTouchPoint (OTP), which prints and mails newsletters for CareSource. On April 28, 2022, OTP learned of an attack where files containing member information were locked by the attacker (ransomware). Affected data included names, addresses, diagnoses, medications, allergies, health screenings, immunizations, vital signs, and plan names. Social Security numbers and financial information were not involved. OTP shut down and rebuilt its systems and added technical controls.
- OHIOHHS OCRas victim2022-05-06
CareSource, Inc reported to HHS on 2022-05-06 a Unauthorized Access/Disclosure affecting 959 individuals. Breached information located on Laptop. A workforce member of its business associate provided an unauthorized individual with remote access to his computer via Zoom. PHI involved included names, addresses, dates of birth, diagnoses, lab results, and medications.
- Indiana State AGas victim2022-04-29
CareSource reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-01 and was reported on 2022-04-29. 8 Indiana residents were affected. 959 individuals affected in total.
- Indiana State AGas victim2021-03-22
CareSource, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-14 and was reported on 2021-03-22. 1 Indiana residents were affected. 17 individuals affected in total.
- OHIOHHS OCRas victim2020-11-11
CareSource Indiana, Inc reported to HHS on 2020-11-11 a Unauthorized Access/Disclosure affecting 10021 individuals. Breached information located on Paper/Films. A business associate inadvertently mailed PHI (names, clinical info, diagnoses) to wrong recipients. The CE implemented additional administrative safeguards.
- OHIOHHS OCRas victim2020-11-11
CareSource reported to HHS on 2020-11-11 a Unauthorized Access/Disclosure affecting 8730 individuals. Breached information located on Paper/Films. A business associate inadvertently mailed PHI to wrong recipients.
- OHIOHHS OCRas victim2020-11-11
CareSource West Virginia Co reported to HHS on 2020-11-11 a Unauthorized Access/Disclosure affecting 1587 individuals. Breached information located on Paper/Films. A business associate inadvertently mailed PHI (names, clinical info, diagnoses) to wrong recipients. The CE implemented additional administrative safeguards.