[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f14juxwx0253vj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a7052fd1a5649189bfdfd1e","CommunityCareAlliance2024","Community Care Alliance 2024 Data Breach","community-care-alliance-2024","communitycareri.org","2024-07-01T00:00:00.000Z","2026-08-03T08:36:13.893Z","HHS OCR report, organization notification reporting, and healthcare-security coverage","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16,17,18],"https:\u002F\u002Fstraussborrelli.com\u002F2025\u002F03\u002F07\u002Fcommunity-care-alliance-data-breach-investigation\u002F","https:\u002F\u002Fwww.hipaajournal.com\u002Fcommunity-care-alliance-data-breach-settlement\u002F","https:\u002F\u002Fwww.communitycareri.org\u002F",114975,"known",null,"people","High",[25,26,27,28,29,30,31],"Names","Physical addresses","Dates of birth","Social security numbers","Driver's license numbers","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2024 Community Care Alliance data breach\u003C\u002Fstrong> came to light after the Rhode Island health and social-services organization detected unusual activity on its network in July 2024. The investigation found that an unauthorized person accessed systems between July 1 and July 5 and may have viewed and obtained sensitive information.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a network-server Hacking\u002FIT Incident affecting 114,975 people. Later litigation and settlement reporting described it as a Rhysida-attributed ransomware attack involving data exfiltration.\u003C\u002Fp>\u003Ch2>How was the Community Care Alliance breach confirmed?\u003C\u002Fh2>\u003Cp>The HHS OCR entry connects Community Care Alliance, the Rhode Island healthcare provider, the total of 114,975 people, a March 2025 report, and a network server in one event. The organization's official site confirms its Woonsocket identity and its mental health, addiction, housing, and basic-needs programs.\u003C\u002Fp>\u003Cp>An independent incident review, citing the organization notice, reports the July 1–5 access window, completion of the file review around January 8, 2025, and the disclosed information types. Healthcare-security reporting also connects discovery on July 6, the 114,975-person scope, the Rhysida attribution, and data exfiltration to the same event.\u003C\u002Fp>\u003Ch2>What happened in July 2024?\u003C\u002Fh2>\u003Cp>An unauthorized person accessed Community Care Alliance systems between July 1 and July 5, 2024. The organization detected the attack on July 6; the event caused a network disruption and prompted an investigation with third-party specialists.\u003C\u002Fp>\u003Cp>Later reporting described the event as a Rhysida ransomware attack and said the group claimed to have exfiltrated about 2.5 terabytes of data. The organization investigation confirmed possible unauthorized viewing and acquisition, while public sources do not disclose the initial access method or technical vulnerability.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Potentially affected information included names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical information, and health insurance information. Medical fields could include diagnoses or conditions, lab results, medications, patient identification numbers, provider names, and treatment information.\u003C\u002Fp>\u003Cp>Community Care Alliance said the information involved varied by person. Passwords, email addresses, payment cards, and bank accounts are not included in this record because the public incident disclosures do not confirm those fields.\u003C\u002Fp>\u003Ch2>Why do these details matter?\u003C\u002Fh2>\u003Cp>Identity information exposed together with detailed health information can increase the risk of identity theft, fraudulent accounts or insurance claims, and targeted scams. Social Security and driver's license numbers cannot be changed easily, so careful monitoring may be necessary over the long term.\u003C\u002Fp>\u003Cp>Callers who know a real diagnosis, medication, or provider name may appear more convincing. Possessing those details does not prove that a sender represents Community Care Alliance, an insurer, or a clinic, and unexpected requests should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>How did the organization respond?\u003C\u002Fh2>\u003Cp>Community Care Alliance investigated with third-party specialists, implemented additional technical safeguards, and notified affected people. Eligible individuals were offered 12 months of credit monitoring and identity-protection services.\u003C\u002Fp>\u003Cp>The review to identify affected files and people was completed around January 8, 2025. A later lawsuit ended in a $1.09 million settlement in which Community Care Alliance denied wrongdoing; the settlement does not constitute an admission about the technical cause of the event.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>People who received a notice should review credit reports, financial accounts, and health insurance explanations for unfamiliar accounts, transactions, claims, or services. Suspicious activity should be reported to the relevant financial institution, insurer, credit bureaus, and appropriate authorities when necessary.\u003C\u002Fp>\u003Cp>Social Security numbers, health information, passwords, and one-time verification codes should not be shared in unexpected emails, messages, or calls. Requests claiming to come from Community Care Alliance or another organization should be verified through contact details on the official website rather than links or phone numbers in the message.\u003C\u002Fp>","","Community Care Alliance 2024 Data Breach (115 Thousand People Affected)","The Community Care Alliance breach affected identity and health information belonging to 114,975 people. Review the Rhysida attack and safety steps.","\u002Fuploads\u002Flogo\u002Fcommunity-care-alliance-official.webp",false,{"name":39,"sector":40,"country":41,"website":18,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":21},"Community Care Alliance","Healthcare","United States"]