Menu
Browse

Cyber Incident Victim: Allaire Healthcare Group

Date:

Nov 2021

Location:

United States of America

Summary

Allaire Healthcare Group experienced an unauthorized breach of an employee email account, compromising protected health information of 13,148 individuals. The intrusion was confined to a single account, exposing names, Social Security numbers, financial details, medical histories, treatment information, and insurance data, though forensic analysis found no evidence of data exfiltration or subsequent misuse. The organization secured the account promptly after detecting suspicious activity and confirmed the scope through a comprehensive review.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 24, 2021, Allaire Healthcare Group detected suspicious activity in an employee’s email account at its Freehold, NJ-based residential healthcare facilities. The organization immediately secured the compromised account and its email system to prevent further unauthorized access. A forensic investigation determined the breach was confined to a single email account accessed by an unauthorized individual between November 10 and November 24, 2021. The timeframe indicated the threat actor maintained persistent access for two weeks before detection. Allaire operates five facilities providing subacute care, dementia care, and respite care across the tri-state area, though the breach did not directly compromise clinical systems beyond the targeted email account.

Cyber Incident Image

The organization completed a programmatic and manual review of the affected email account on March 18, 2022, confirming exposure of protected health information for 13,148 individuals. Compromised data included first and last names, Social Security numbers, Allaire-issued unique client identifiers, driver’s license numbers, passport numbers, financial account details, payment card information, medical histories, treatment/diagnosis records, prescription data, and health insurance information. Investigators found no evidence that the unauthorized actor viewed or downloaded the exposed data, and no instances of actual or attempted misuse were reported following the incident. The breach notification did not specify whether multi-factor authentication was enabled on the compromised account or detail the exact method of initial compromise. Allaire’s response focused on securing the account, conducting forensic analysis, and reviewing the scope of impacted data over a four-month investigation period.

Sources
Sources available to members
1 source