CareSource reported a cybersecurity incident involving its third-party vendor, OneTouchPoint (OTP). On April 28, 2022, OTP systems were locked by an attacker, indicating a ransomware attack. Files containing member personal information (names, addresses, member IDs, age, gender) and health data (diagnoses, medications, allergies, health screenings, vital signs, immunizations, plan names) were encrypted. OTP shut down and rebuilt systems, adding technical controls. No SSN or financial account data was impacted.