[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxv6TdwE8ITtc58-ODY9zJjpqz9d7kLsH70LSd-0UppM":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":24,"source":25,"isVerified":4,"isSpamList":26,"isSensitive":4,"processingStatus":27,"logoUrl":28,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":29},"6a676edae08f8a32195ff6c4","EvergreenHealthcareGroup2025","Evergreen Healthcare Group 2025 Data Breach","evergreen-healthcare-group-2025","evergreenhcg.com",{"name":12,"sector":13,"country":14,"website":10},"Evergreen Healthcare Group","Healthcare","United States","2025-12-03T00:00:00.000Z","2026-07-27T14:44:42.843Z","2026-07-27T16:11:12.916Z",11795,[20,21,22,23],"Full names","Social Security numbers","Dates of birth","Medical information","\u003Cp>\u003Cstrong>The Evergreen Healthcare Group 2025 data breach\u003C\u002Fstrong> involved unauthorized activity detected in a cloud-based healthcare platform operated by Couve Healthcare Consulting, LLC under the Evergreen Healthcare Group (EHG) trade name. EHG said it became aware of the activity on or about December 3, 2025, activated its incident response plan, and found evidence that an unauthorized party may have accessed certain files.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights portal lists Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group in Washington with 11,795 affected people. The federal row identifies EHG as a business associate, classifies the event as a Hacking\u002FIT Incident, and lists Electronic Medical Record as the location.\u003C\u002Fp>\u003Ch2>How Was the Evergreen Healthcare Group Incident Verified?\u003C\u002Fh2>\u003Cp>The primary source is the “Notice of Data Breach” PDF dated February 25, 2026 and hosted on EHG's own evergreenhcg.com domain. In EHG's own words, it describes the December 3 discovery, the cloud-based healthcare platform, possible file access, reviewed data types, security measures, and the 855-522-1474 assistance line.\u003C\u002Fp>\u003Cp>The second source is the HHS\u002FOCR federal row reported February 24, 2026 for 11,795 people. The third is the Couve Healthcare Consulting DBA Evergreen Healthcare Group document published as matter “2026-272” in Massachusetts's official mass.gov notice archive. The sources are consistent about the entity, nature of the incident, and notification process.\u003C\u002Fp>\u003Ch2>Scope Between Golden Sonora Care Center and EHG\u003C\u002Fh2>\u003Cp>The PDF on EHG's website is a substitute notice issued on behalf of Golden Sonora Care Center and in EHG's capacity as its business associate. It therefore represents a customer-specific notice connected to the incident on EHG's platform. The federal HHS row instead names Couve Healthcare Consulting DBA Evergreen Healthcare Group as the reporting entity and identifies its business-associate status.\u003C\u002Fp>\u003Cp>The 11,795 figure is the total in the HHS\u002FOCR row for EHG; the official PDF does not say that every one of those people belongs only to Golden Sonora Care Center. This record centers on the EHG event without merging the entities, identifies Golden Sonora as the customer covered by the notice, and does not invent a customer allocation or facility-level count that the sources do not provide.\u003C\u002Fp>\u003Ch2>Incident Timeline\u003C\u002Fh2>\u003Cp>EHG says it learned of unauthorized activity in its cloud-based healthcare platform on or about December 3, 2025 and immediately implemented its incident response plan. The public notice does not disclose the actor's first entry date or the length of access. The incident date is based on the earliest technical activity that can be verified from public sources.\u003C\u002Fp>\u003Cp>The organization then reviewed potentially impacted files to identify the information present and related individuals. After completing the review, it notified affected people by U.S. First Class Mail on February 24, 2026. The February 25 website document is a substitute notice intended to reach people who could not receive direct notice; neither notification date is presented as the attack start.\u003C\u002Fp>\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\u003Cp>According to EHG's official notice, information potentially subject to unauthorized access included names, Social Security numbers, dates of birth, and medical information. The document says the files “may have been accessed” and that information “may have been subject to unauthorized access”; it does not claim that every field was viewed for every individual.\u003C\u002Fp>\u003Cp>The combination may vary by person. A Social Security number combined with a date of birth can increase identity-fraud risk, while medical information can create longer-lasting privacy and medical identity risks.\u003C\u002Fp>\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\u003Cp>The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person. It is not a number of files, documents, medical records, or rows downloaded by an actor. The HHS row also connects the hacking\u002FIT incident to an electronic medical record environment.\u003C\u002Fp>\u003Cp>When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.\u003C\u002Fp>\u003Ch2>Organization Response and Steps for Individuals\u003C\u002Fh2>\u003Cp>EHG said it secured the impacted platform, verified the security of internal systems, and began implementing additional technical safeguards, enhanced security measures, and updated procedures. It offered affected individuals complimentary credit monitoring and identity theft restoration services. At the time of the notice, EHG said it had received no reports of related misuse of personal information.\u003C\u002Fp>\u003Cp>Recipients should follow enrollment instructions in their letter, monitor credit reports and financial accounts, and review unfamiliar healthcare activity. Suspicious communications invoking EHG can be verified through evergreenhcg.com or the 855-522-1474 line, available weekdays from 8:00 a.m. to 8:00 p.m. Eastern Time.\u003C\u002Fp>","Official Evergreen Healthcare Group notice, HHS\u002FOCR breach report, and Massachusetts filing",false,"completed","\u002Fuploads\u002Flogo\u002Fevergreenhcg_com.svg","Medium"]