The cCARE data breach stemmed from an email phishing incident that reached accounts containing patient information. California Cancer Associates for Research and Excellence (cCARE), which describes itself as the largest full-service private oncology and hematology practice in California, notified patients in 2025. If you are a current or former cCARE patient and received a notification letter, your information may have been involved — and you may have legal rights.
What Happened?
According to cCARE’s notice filed with the California Attorney General, on June 13, 2025 the practice learned that an email phishing incident had resulted in unauthorized access to patient information held in a small number of email and SharePoint accounts. The notice states that measures were taken immediately in response and that an investigation was conducted.
The investigation determined that unauthorized parties accessed those accounts between December 13, 2024 and December 16, 2024. As the notice explains, although the likely purpose of the unauthorized access was to perpetuate an email phishing scheme, certain emails and SharePoint files were in fact accessed by the unauthorized parties.
A review was then performed of the emails, attachments, and SharePoint files that may have been accessed in order to identify affected individuals. The California Attorney General’s breach records list the cCARE Fresno notice as submitted on June 27, 2025, and identify the breach dates as December 13 through December 16, 2024.
A Phishing Incident That Reached Beyond One Clinic
cCARE is affiliated with Integrated Oncology Network (ION), an organization that provides administrative and clinical support to community-based oncology and urology practices and is reported to be headquartered in Nashville, Tennessee.
Reporting on this incident indicates it was not limited to a single clinic. Trade and security press have reported that the phishing attack affected roughly two dozen or more cancer care and oncology practices across multiple states, each filing separate breach reports with federal regulators, with combined totals reported in the range of 120,000 to 130,000 individuals. Published figures vary between outlets, and no single official total has been confirmed here.
Security trade reporting also indicates that three separate cCARE practices — in Fresno, High Desert, and San Diego — appeared among the entities reporting breaches to the HHS Office for Civil Rights in connection with this incident.
What Information Was Involved?
This is an area where the public record is limited, and it is worth being precise.
The sample notice cCARE filed with the California Attorney General confirms that the affected files contained each recipient’s name, followed by additional data elements that were filled in individually on each letter rather than listed in the public sample. The notice therefore does not publicly enumerate the full set of categories.
Law firm investigations and breach-tracking sites reporting on this incident have described a broader set of categories as potentially involved, including Social Security number, address, date of birth, financial account information, diagnoses, lab results, medications, treatment information, health insurance and claims information, provider names, and dates of treatment. These descriptions come from secondary reporting rather than from the public notice, and have not been confirmed against the filed document here.
Your own notification letter is the only reliable guide to which categories applied to you. For cancer patients, the categories described in that reporting would be a significant concern, because oncology records can reveal private details about diagnosis and treatment that cannot be reissued once disclosed.
What Is cCARE Doing?
cCARE’s notice states that, to date, there is no evidence that any specific individual’s information has been misused.
Affected patients were offered complimentary enrollment in Epiq Privacy Solutions ID credit monitoring. The notice describes the product as including credit monitoring with alerts, Social Security number monitoring, dark web monitoring, credit report lock and freeze assistance, identity restoration services, and up to $1 million in identity theft insurance with no deductible. The coverage length is filled in individually on each letter and is not stated in the public sample.
To enroll, the notice directs affected individuals to use the activation code provided in their letter at www.privacysolutionsid.com before the enrollment deadline stated there. cCARE also stated that additional cybersecurity training is being provided to staff.
Why This Breach Warrants Scrutiny
Two aspects stand out. First, the unauthorized access occurred in December 2024, but the California notice was filed and patient letters began in late June 2025 — roughly six months later. Second, because the compromise involved accounts connected to a broader affiliated network rather than a single practice, patients had no visibility into or control over the security practices at issue.
Under HIPAA, a healthcare provider remains responsible for protecting patient information even where that information is handled through an affiliated organization or business associate. A compromise at that level does not diminish patients’ rights.
Your Rights After the cCARE Data Breach
If your information was involved in the cCARE data breach, you may be entitled to compensation for:
- The unauthorized access to your personal and protected health information
- Costs associated with credit monitoring and identity protection
- Actual financial losses resulting from identity theft, medical fraud, or insurance fraud
- Emotional distress caused by the exposure of private medical information
- Harm associated with any delay in receiving notice of the incident
Contact Wilshire Law Firm for a Free Consultation
If you received a notification letter from cCARE or Integrated Oncology Network, Wilshire Law Firm wants to hear from you. Our legal professionals understand how distressing it is to learn that private cancer treatment records may have been exposed, and can review your situation at no cost.
We take no fees unless you get paid.
Contact us online to speak with a legal professional today.

