Alvita Care Holdings, a provider of home care services, discovered on June 22, 2026, that an unknown third party claimed to possess company data. An investigation, aided by a cybersecurity firm, revealed that an unauthorized party accessed and extracted data from Alvita Care's systems between March 25 and June 26, 2026. This access occurred through a third-party software application used to manage client services.
The compromised data types include financial account codes, credit and debit card numbers, Social Security numbers, names, dates of birth, addresses, government IDs, and medical information. While the Vermont Attorney General's office confirmed exposure for approximately three Vermont residents, the nationwide impact is not fully quantified. The company operates in New York, New Jersey, and surrounding areas. The breach has been reported to both the Vermont and Massachusetts Attorney Generals.
Details can continue to emerge, and notifications to affected individuals may be delayed. The actual attorney general filing texts or the company's direct notification letter were not available, meaning the precise scope and exact number of affected individuals are not fully verifiable from the current public sources.