Elara Caring told patients that an unauthorized actor reached home-care documentation sitting with an outsourced document-signing vendor during two windows in November 2025, while stressing that Elara-operated systems were not the intrusion locus.
Vendor outreach on December 12 2025 kicked off forensics; Elara concluded on March 12 2026 that PHI rode inside the stolen files. Regulator-facing samples carried May 12 2026 letter dates, and Massachusetts breach filings enumerated 714 in-state residents in the indexed packet—useful as a documented floor even though nationwide totals may take additional state disclosures to stabilize.
Canonical record: Elara Caring 2026 vendor incident on BreachHistory.
Sources: Massachusetts AG breach filing (sample notice PDF), ClaimDepot summary