[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f14oq1pe0obi33":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":36,"seoTitle":37,"seoTitleEn":38,"seoDescription":37,"seoDescriptionEn":39,"logoUrl":40,"isVerified":4,"isSensitive":4,"isSpamList":41,"isMalware":41,"company":42},"6a70a013582f14d34d0cf903","CioxDatavant2024","Ciox \u002F Datavant 2024 Data Breach","ciox-datavant-2024","datavant.com","2024-05-08T00:00:00.000Z","2026-08-03T14:05:05.982Z","2026-08-03T14:07:24.024Z","HHS OCR, court-authorized settlement notice, and independent healthcare breach reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[15,17,18,19],"https:\u002F\u002Fwww.datavantdataincidentsettlement.com\u002F","https:\u002F\u002Ffiles.openclassactions.com\u002Fpdf\u002Fciox-health-datavant-group-data-security-incident-class-action-settlement-notice.pdf","https:\u002F\u002Fwww.hipaajournal.com\u002Fesha-citadel-healthcare-datavant-smile-design-breach\u002F",320702,"known",null,"people","High",[26,27,28,29,30,31,32,33,34,35],"Names","Dates of birth","Physical addresses","Contact information","Social Security numbers","Financial account information","Driver's license numbers","Passport numbers","Health information","Digital signatures","\u003Cp>\u003Cstrong>The 2024 Ciox Health \u002F Datavant data breach\u003C\u002Fstrong> followed a phishing response that enabled unauthorized access to one corporate email account between May 8 and May 9, 2024. The U.S. Department of Health and Human Services breach record reports 320,702 affected people.\u003C\u002Fp>\u003Cp>Ciox Health operates as Datavant Group, a healthcare information technology company. The company provides services intended to make health data usable across different systems.\u003C\u002Fp>\u003Ch2>How did the Ciox \u002F Datavant data breach happen?\u003C\u002Fh2>\u003Cp>Datavant identified suspicious activity in its email environment on May 9, 2024. Its investigation found that phishing messages had been sent to a limited number of users and that one employee's response allowed an attacker to access a single email account from May 8 to May 9.\u003C\u002Fp>\u003Cp>The company reviewed affected messages and attachments to identify the people and data controllers within scope. Relevant parties and individuals were notified after that work was completed.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed fields included names, dates of birth, addresses and contact information, and Social Security numbers.\u003C\u002Fp>\u003Cp>Financial account details, driver's license and passport numbers, health information, account credentials, and digital signatures may also have been involved for some people. Not every category applied to every affected individual.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The current HHS Office for Civil Rights breach record reports 320,702 affected individuals. Earlier notices carried smaller interim totals; this catalog entry uses the updated federal total for the same event and does not add those earlier figures separately.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers combined with dates of birth and addresses can increase the risk of identity theft or fraudulent account applications. Financial-account and government-identity information can also be used in fraud attempts.\u003C\u002Fp>\u003Cp>Health information and stolen email context may help an attacker impersonate a company, healthcare provider, or financial institution in a convincing message. Unexpected communications should be verified through an independent official channel.\u003C\u002Fp>\u003Ch2>How did Datavant respond?\u003C\u002Fh2>\u003Cp>Datavant said it conducted a forensic investigation, reconfigured email security settings, implemented additional technical safeguards, and updated security-software rules. Eligible individuals were offered identity monitoring and protection services.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports and financial accounts for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>Before opening links in an unexpected request that uses identity-document or health details, recipients should verify the sender independently. Suspected financial, medical, or identity misuse should be reported directly to the relevant institution.\u003C\u002Fp>","","Ciox \u002F Datavant Data Breach (320.7 Thousand People Affected)","The Ciox \u002F Datavant data breach affected 320,702 people and may have exposed identity, financial, account, and health information.","\u002Fuploads\u002Flogo\u002Fdatavant-official.svg",false,{"name":43,"sector":44,"country":45,"website":46,"websiteArchiveUrl":37,"websiteStatus":37,"websiteCheckedAt":22},"Ciox Health, LLC d\u002Fb\u002Fa Datavant Group","Healthcare","United States","https:\u002F\u002Fwww.datavant.com\u002F"]