CareSource
ent_efed378fa56de50e108c49a7
Disclosures
8
State AG · Leak Site · HHS OCR · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
10,021
nationwide · HHS OCR OH
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- CareSource
- Normalized
- caresource— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- caresource.com
Disclosure history (8)newest first
- ⛰️New Hampshire State AGas victim2023-08-30
CareSource, a managed care organization, reported a breach involving its MOVEit file transfer vendor. The CL0P ransomware group exploited a vulnerability on May 31, 2023, exfiltrating data including PHI, SSNs, and member details. CareSource discovered the breach on June 27, 2023, patched the system, and engaged Kroll for forensics. 70 New Hampshire residents were affected. Notifications began August 25, 2023, offering credit monitoring.
- 🌲Washington State AGas victim2023-08-30
CareSource, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-27 and filed notice on 2023-08-30. 581 Washington residents were affected. 64 days elapsed between awareness and notification. 27 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2023-08-28
CareSource experienced a security breach involving its vendor MOVEit. On May 31, 2023, the MOVEit software was hacked, allowing an unauthorized actor to access and copy data used to manage member benefits. CareSource learned of its inclusion in the breach on June 27, 2023. The compromised data included protected health information (PHI) such as names, addresses, dates of birth, Social Security numbers, member IDs, plan names, health conditions, medications, allergies, and diagnoses. CareSource patched the software on June 1, 2023, cutting off the attacker's access. The company is conducting a full investigation and has offered two years of credit monitoring through Kroll to affected individuals.
- 🍁Vermont State AGas victim2023-08-25
CareSource disclosed a data breach affecting its members due to a vulnerability in Progress Software's MOVEit transfer software. The incident, discovered on June 27, 2023, involved the exfiltration of protected health information (PHI) and personally identifiable information (PII), including SSNs and health conditions. CareSource patched the software and engaged Kroll to provide two years of credit monitoring to affected individuals.
- GLOBALLeak Siteas victim2023-06-29
CareSource - Health Care with Heart
- 🐻California State AGas victim2022-08-01
CareSource reported a cybersecurity incident involving its third-party vendor, OneTouchPoint (OTP). On April 28, 2022, OTP systems were locked by an attacker, indicating a ransomware attack. Files containing member personal information (names, addresses, member IDs, age, gender) and health data (diagnoses, medications, allergies, health screenings, vital signs, immunizations, plan names) were encrypted. OTP shut down and rebuilt systems, adding technical controls. No SSN or financial account data was impacted.
- OHHHS OCRas victim2020-11-11
CareSource Indiana, Inc reported to HHS on 2020-11-11 a Unauthorized Access/Disclosure affecting 10021 individuals. Breached information located on Paper/Films. A business associate inadvertently mailed PHI (names, clinical info, diagnoses) to wrong recipients. The CE implemented additional administrative safeguards.
- OHHHS OCRas victim2020-11-11
CareSource West Virginia Co reported to HHS on 2020-11-11 a Unauthorized Access/Disclosure affecting 1587 individuals. Breached information located on Paper/Films. A business associate inadvertently mailed PHI (names, clinical info, diagnoses) to wrong recipients. The CE implemented additional administrative safeguards.