[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7cDsPxqCf0liV3ov0c7H0JkNrRfBYG6OVUiQfQ7M9yA":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"severity":30,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66ed53790bf5af12cbf1bc","ElaraCaring2025","Elara Caring 2025 Data Breach","elara-caring-2025","elara.com",{"name":12,"sector":13,"country":14,"website":10},"Elara Caring","Healthcare","United States","2025-11-04T00:00:00.000Z","2026-07-27T05:32:03.303Z",22172,[19,20,21,22,23,24,25,26],"Personal information","Protected health information","Names","Addresses","Dates of birth","Social Security numbers","Medical record information","Health insurance information","\u003Cp>\u003Cstrong>The Elara Caring 2025 data breach\u003C\u002Fstrong> was an unauthorized-access incident in the systems of a third-party vendor used by the home-health provider for document management and signing on November 4–6 and November 14–17, 2025. Elara’s official notice says the actor accessed and\u002For downloaded documents associated with patients from the vendor’s system.\u003C\u002Fp>\n\u003Cp>The public record maintained by the U.S. Department of Health and Human Services Office for Civil Rights lists 22,172 affected people and classifies the event as a Hacking\u002FIT Incident involving Email. Elara said its own systems were not affected. LeakData imported no patient rows; importedRecordCount is zero, and this entry contains incident metadata only.\u003C\u002Fp>\n\u003Ch2>How Was the Elara Caring Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is Elara Caring’s four-page Notice of Data Security Incident dated May 12, 2026. It confirms the vendor-notification date, two access windows, download of patient documents, absence of impact to Elara systems, investigation, termination of the vendor relationship, and twenty-four months of protective services.\u003C\u002Fp>\n\u003Cp>The second source is the HHS OCR breach portal, which provides the current federal total of 22,172 people. The third is HIPAA Journal’s May 18, 2026 report, which independently describes the timeline, data types, and vendor event from the official letter. A Massachusetts consumer-affairs report also corroborates involvement of Social Security numbers and medical records.\u003C\u002Fp>\n\u003Ch2>What Happened in November 2025?\u003C\u002Fh2>\n\u003Cp>Elara used an outside provider to manage and electronically sign documents related to home-health services. On December 12, 2025, the vendor told Elara that an unauthorized person had accessed and\u002For downloaded documents associated with Elara patients in its system during November 4–6 and November 14–17.\u003C\u002Fp>\n\u003Cp>Elara opened a comprehensive review and determined on March 12, 2026 that the downloaded documents contained patient personal information. The breachDate field uses November 4, 2025, the first confirmed day of access. Elara’s letter does not name the vendor; HIPAA Journal identifies it as Doctor Alliance from the matching dates, but this entry does not present that as an Elara attribution.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The fields varied by person and may include names, addresses, dates of birth, Social Security numbers, medical-record information, and health-insurance information. The person-specific field in the sample notice is redacted in the public copy; the categories are supported together by the regulatory report and independent healthcare-security coverage.\u003C\u002Fp>\n\u003Cp>The sources do not say every field belonged to all 22,172 people. This entry therefore creates no subgroup counts and adds no undisclosed passwords, payment cards, or bank accounts. Although the company letter confirms download of documents, the evidence does not establish public release, sale, or transfer of the files to a named ransomware group.\u003C\u002Fp>\n\u003Ch2>Why Was the Scope Updated to 22,172 People?\u003C\u002Fh2>\n\u003Cp>The pwnCount and totalRecords fields use the 22,172-person value in HHS OCR’s current public row dated June 23, 2026. HIPAA Journal reported 10,490 people on May 18 from an earlier federal-report snapshot, including 3,300 Texas residents. The later federal total is therefore used as the main value.\u003C\u002Fp>\n\u003Cp>The two figures reflect notification scope at different times for the same incident; 10,490 is not subtracted or treated as a separate new breach. The value of 22,172 counts affected people in the federal record, not documents, home-care visits, or data elements. Because the sources provide no completed state-by-state distribution, this entry creates no new regional totals.\u003C\u002Fp>\n\u003Ch2>How Did Elara Change Its Vendor Relationship?\u003C\u002Fh2>\n\u003Cp>Elara terminated its relationship with the third party after the event. The organization said it was reviewing information-security policies, procedures, and controls, especially those relating to outside vendors, and would implement appropriate improvements to reduce the risk of a similar incident.\u003C\u002Fp>\n\u003Cp>Affected people received twenty-four months of complimentary credit monitoring and identity-remediation services through Cyberscout. The notice recommends activating the service within its enrollment period. Because no unauthorized access to Elara’s network was identified, this entry does not characterize the event as a direct attack on Elara systems; the confirmed scope is patient documents in the vendor environment.\u003C\u002Fp>\n\u003Ch2>What Should Affected Patients Do?\u003C\u002Fh2>\n\u003Cp>Notice recipients should activate the Cyberscout service before the deadline in their letter and regularly review credit reports, online and financial accounts, health-insurance explanation-of-benefits statements, and medical-service histories for unfamiliar activity. A suspicious entry should be reported through an official channel for the relevant organization.\u003C\u002Fp>\n\u003Cp>The combination of Social Security numbers with medical and insurance information creates lasting identity-theft and healthcare-fraud risk. Identity details should not be shared through unexpected links claiming to represent Elara Caring, Cyberscout, Doctor Alliance, or an insurer; contact should begin through a verified number. LeakData does not host, distribute, or provide search access to downloaded patient documents.\u003C\u002Fp>","Official Elara Caring notice confirming third-party system access and patient-document download",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Felara_com.png"]