2024 PointClickCare — unauthorized access via compromised credentials; long-term-care PHI exposure (facility notices)
Data compromised
PHI and resident identifiers as described in facility-issued breach letters summarized in legal and trade press
Technical writeup
EHR and care-coordination vendor PointClickCare told customers it discovered unauthorized activity on July 20, 2024, involving credential-based access to systems holding resident health information for downstream skilled-nursing and long-term-care facilities; public summaries and substitute notices through late 2024 described patient names, clinical and demographic fields, and in some facility letters government identifiers. Aggregate U.S. resident counts were fragmented across many facility filings rather than one vendor-wide headline number in open sources reviewed at row creation.
Root cause
Use of compromised account credentials against vendor-accessible clinical systems (per substitute-notice narratives)