The covered entity (CE), CareSource, reported that a workforce member of its business associate (BA) provided an unauthorized individual with remote access to his computer via Zoom. This breach affected the protected health information (PHI) if 959 individuals. The PHI involved included names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, the affected individuals, and the media. In response to the breach, the BA implemented additional administrative, technical, and security safeguards. Staff were retrained on methods to better protect PHI.
2026-09-25 · sector: other to insurance · backfill source
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 959 · backfill source
2026-09-25 · disclosed: 2022-08-01 to 2022-05-06 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), CareSource, reported that a workforce member of its business associate (BA) provided an unauthorized individual with remote access to his computer via Zoom. This breach affected the protected health information (PHI · backfill source