Skip to content

Allcare medical Management

Disclosed Jul 22, 20242 years ago16,378 affectedConfirmed

Official notice

The business associate (BA), Allcare Medical Management, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 16,378 individuals. The PHI involved included names, dates of birth, Social Security numbers, and other demographic information. The BA notified HHS, affected individuals, the media, and posted substitute notice online. In its mitigation efforts, the BA implemented additional administrative, technical, and security safeguards to better protect its PHI. In addition, the BA retrained its workforce members on email security precautions. OCR provided technical assistance regarding the HIPAA Rules.

What is known

People affected16,378 (as reported to HHS)
DisclosedJul 22, 2024
HappenedApr 16, 2024
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CAJul 22, 2024
HHS archivetotalJul 22, 202416,378
California AGresidents of CAAug 2, 2024
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 16378 · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), Allcare Medical Management, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 16,378 individuals. The PHI involved included names, date · backfill source
  • 2026-09-25 · disclosed: 2024-08-02 to 2024-07-22 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Allcare medical Management

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.