Elara Caring experienced a data breach stemming from an unauthorized access event at a third-party vendor. The breach occurred between November 4-6 and November 14-17, 2025. Elara Caring was notified by the vendor on December 12, 2025, and subsequently determined on March 12, 2026, that patient information was compromised. The company began notifying consumers on March 12, 2026, with physical mailings sent on May 12, 2026. A filing with the Massachusetts Office of Consumer Affairs and Business Regulation on May 12, 2026, confirmed the incident as a hacking/IT event.
The breach involved sensitive data, specifically names, Social Security numbers, and health records. At least 714 Massachusetts residents were affected, though a nationwide impact has not been publicly disclosed. While Elara Caring serves over 60,000 patients daily across multiple regions, the full extent of individuals affected remains unclear. No financial data was reported as compromised. The investigation revealed that Elara Caring's internal systems were not impacted, and the company terminated its relationship with the compromised third-party vendor.
While details can emerge later and notices may be delayed, the company has offered 24 months of free credit monitoring.