Menu
Browse

Cyber Incident Victim: Elara Caring

Date:

Dec 2020

Location:

United States of America

Summary

A home-based care provider experienced a security incident involving unauthorized access to corporate email accounts containing sensitive employee and patient information, potentially including names, Social Security numbers, financial details, insurance information, and other personally identifiable data. The organization discovered the breach and subsequently notified over 100,000 affected individuals, though no evidence confirmed data exfiltration or misuse by the intruder. The compromised accounts held both workforce and client records, with reported impacts encompassing driver's licenses, passport numbers, and employer identification details. While the entity maintains no indication of actual information theft occurred, the incident was formally reported to federal health authorities as affecting approximately 100,500 patients.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Elara Caring, a home-based care provider, experienced a data security breach involving unauthorized access to corporate email accounts. The organization discovered the incident in mid-December 2019 and subsequently initiated notifications to over 100,400 patients beginning in November 2020. Compromised email accounts contained both employee and patient information, though the specific timeframe of the breach and method of detection were not disclosed publicly. Elara Caring’s website notification confirmed the exposure of sensitive data but did not identify the attackers or their motives. The breach was reported to the U.S. Department of Health and Human Services (HHS) on February 24, 2020, with 100,487 patients listed as affected, though this entry appeared in the public breach database months later.

Cyber Incident Image

The compromised email accounts held personally identifiable information (PII) and protected health information (PHI), including names, addresses, Social Security numbers, driver’s license numbers, Employer ID numbers, financial or bank account details, dates of birth, email addresses with passwords, insurance information, insurance account numbers, and passport numbers. Elara Caring explicitly stated no evidence indicated data exfiltration, access, or misuse by the intruder at the time of notification. The organization directed affected individuals to review its website notice for additional details but did not disclose technical remediation steps or third-party forensic involvement. Public records show the breach impacted individuals across multiple data categories, though the geographic scope and operational disruptions remained unspecified. HHS records confirmed the incident as one of the larger healthcare breaches reported in early 2020 based on patient count.

Sources
Sources available to members
1 source