[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDy2fgyhYQOimHxiQEFa-jIVZ2orrubvyd18Trm4-2so":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":33,"source":34,"isVerified":4,"isSpamList":35,"isSensitive":4,"processingStatus":36,"logoUrl":37,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":38},"6a67677ed8879288a9dbd168","CedarPointHealth2023","Cedar Point Health 2023 Data Breach","cedar-point-health-2023","cedarpointhealth.com",{"name":12,"sector":13,"country":14,"website":10},"Cedar Point Health, LLC","Healthcare","United States","2023-06-16T00:00:00.000Z","2026-07-27T14:13:18.666Z","2026-07-27T16:11:12.390Z",23114,[20,21,22,23,24,25,26,27,28,29,30,31,32],"Names","Addresses","Dates of birth","Social Security numbers","Taxpayer identification numbers","Driver's license or state ID numbers","Passport numbers","Financial account information","Health insurance information","Clinical notes","Diagnoses","Procedures","Treatment records","\u003Cp>\u003Cstrong>The Cedar Point Health 2023 data breach\u003C\u002Fstrong> involved unauthorized access to systems belonging to the Colorado healthcare provider. The organization discovered the incident on June 16, 2023. Its review indicated that personal information and protected health information relating to patients and employees may have been involved, and the event was later reported to federal and state regulators.\u003C\u002Fp>\u003Cp>The U.S. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\u003Ch2>How Was the Cedar Point Health Incident Verified?\u003C\u002Fh2>\u003Cp>The primary evidence is the Cedar Point Health notification package published by the Massachusetts Office of Consumer Affairs and Business Regulation. It contains the consumer letter issued in the organization's name, complimentary Kroll identity monitoring, credit-protection steps, guidance about medical identity theft, and Cedar Point Health's Montrose address. This official state record confirms that the event produced a genuine consumer notification.\u003C\u002Fp>\u003Cp>The second source is the HHS\u002FOCR federal row dated February 12, 2026 for 23,114 people. ClaimDepot's incident summary connects the state letter, HHS record, June 16, 2023 discovery date, and possible data categories. The former incident page on the organization's website now returns 404, so the source chain relies on the persistent regulator document and current federal portal.\u003C\u002Fp>\u003Ch2>What Does the June 16, 2023 Date Mean?\u003C\u002Fh2>\u003Cp>According to the public incident summary, Cedar Point Health discovered the data event on June 16, 2023. No specific attack tool, malware family, or threat-actor name is added because the technical investigation details are not public.\u003C\u002Fp>\u003Cp>The HHS record date of February 12, 2026 does not mean the incident began in 2026; it is the date the federal breach report was entered in the portal. The record name therefore follows the discovery year, 2023. Keeping the delayed report date separate from the event date avoids presenting 2026 as the start of the attack.\u003C\u002Fp>\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\u003Cp>According to the notification sources, the data combination varied by person and may include names, addresses, dates of birth, Social Security or individual taxpayer identification numbers, driver's license or state identification numbers, passport numbers, and financial account information. Potential health fields include insurance details, clinical notes, diagnoses, procedures, and treatment records.\u003C\u002Fp>\u003Cp>It should not be assumed that every field was present for every individual. The HHS row confirms the event type, affected environment, and total person count, while each individual letter is the primary reference for determining which categories apply to its recipient. ClaimDepot's general risk discussion is not treated as evidence of a specific attack method or confirmed misuse absent those claims in the official letter.\u003C\u002Fp>\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\u003Cp>23,114 is the number of affected individuals published in the HHS\u002FOCR portal; it is not a file count, row count, or the number of Massachusetts residents alone. A state filing may describe a smaller in-state subset, but that figure is not added to the nationwide total.\u003C\u002Fp>\u003Cp>The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.\u003C\u002Fp>\u003Ch2>What Are the Identity and Health Risks?\u003C\u002Fh2>\u003Cp>Social Security numbers, taxpayer identification numbers, dates of birth, and government identifiers can increase the risk of fraudulent accounts, tax fraud, or bypassed identity checks. People whose financial account information may be involved should monitor unfamiliar transactions and account changes. Unexpected requests invoking Cedar Point Health or a financial institution should be verified through a known official channel rather than a link in the message.\u003C\u002Fp>\u003Cp>Clinical notes, diagnoses, procedures, treatments, and health insurance information create medical identity-theft and privacy risks. Recipients should review explanations of benefits, insurance claims, and medical bills and report care they did not receive to the provider and insurer. Because medical information cannot be invalidated by changing a password, monitoring should continue over the long term.\u003C\u002Fp>\u003Ch2>What Support Is Available and What Should Users Do?\u003C\u002Fh2>\u003Cp>The official notification package says eligible individuals were offered complimentary identity monitoring through Kroll. Services include credit monitoring, fraud consultation, and identity-theft restoration support. Enrollment codes and deadlines may appear in individual letters, so recipients should follow only the instructions in their own notice and should not disclose a membership code or identity information in unsolicited messages.\u003C\u002Fp>\u003Cp>Users can review free credit reports, consider a fraud alert or credit freeze, and use unique passwords with multi-factor authentication on financial and healthcare accounts. If suspicious activity appears, they should contact the relevant organization through a known number and report identity theft to the appropriate authority when needed.\u003C\u002Fp>","Massachusetts regulator notice, HHS\u002FOCR breach report, and independent incident reporting",false,"completed","\u002Fuploads\u002Flogo\u002Fcedarpointhealth_com.jpg","Medium"]