2026 Elara Caring — third-party document-signing vendor; PHI/SSN-class patient documents (Nov 2025 windows; May notices)
Data compromised
Medical-record-oriented documentation and Social Security numbers per consumer-notice and state-filing characterizations; field mix may vary by patient packet
Technical writeup
Elara Caring, a large U.S. home-health and hospice operator, disclosed that between November 4–6 2025 and November 14–17 2025 an unauthorized party accessed or downloaded patient-related documents held on a third-party vendor platform used for document management and e-sign workflows—Elara’s own systems were not impacted, per the consumer notification letter filed with Massachusetts regulators. The vendor notified Elara on December 12 2025; Elara determined on March 12 2026 that protected health information was among the downloaded material. Letters to affected individuals were dated May 12 2026 in indexed regulatory samples. Massachusetts breach materials referenced 714 affected Massachusetts residents as an early jurisdictional figure while a consolidated nationwide denominator had not been uniformly published in open summaries at initial cataloging. Aggregator and litigation summaries described exposure categories consistent with medical-record content and Social Security numbers; Elara publicly described offering 24 months of Cyberscout (TransUnion) identity services and terminating the vendor relationship.
Root cause
Unauthorized access to a third-party vendor environment storing Elara patient documents (not Elara-hosted primary clinical systems)